Anthropic Adds Built-In Browser to Claude Cowork Desktop App
Anthropic is embedding a dedicated browser into Claude Cowork's desktop app, opening in a side panel whenever a task requires web access. The browser is isolated from the user's own tabs, bookmarks, and passwords, and rolls out this week to Pro, Max, Team, and Enterprise plans.
Anthropic is adding a built-in browser to Claude Cowork's desktop app, giving the AI agent a way to navigate websites directly without relying on a separate browser extension.
According to Anthropic, when a task requires web access, a browser window opens automatically in a side panel within the desktop app. Claude can then load pages, read content, click elements, and type into fields — enabling it to fill out forms or extract data from dashboards, including on portals that lack an API.
Isolated from the user's browser
The embedded browser runs separately from the user's existing browser. Anthropic says Claude cannot see the user's open tabs, bookmarks, or saved passwords in this mode. Users can transfer login credentials into the Cowork browser one page at a time from Chrome, Edge, or Firefox — but Anthropic has excluded banking and email sites from this credential transfer, presumably due to the sensitivity of financial and account-recovery data.
For situations where a user is already signed into a site in their own browser, Anthropic says the existing Chrome extension remains the recommended path, rather than the new isolated browser.
Prompt injection warning
Anthropic flagged prompt injection as a risk with the new capability and is telling users to limit browsing to trusted websites. Prompt injection attacks — where malicious instructions embedded in a webpage attempt to hijack an AI agent's behavior — have become a recurring concern as AI agents gain the ability to autonomously browse and interact with live web content. Anthropic did not disclose specific technical safeguards beyond the isolation of the browser environment and the guidance to avoid untrusted sites.
Rollout details
The feature begins rolling out this week to Claude Cowork users on Pro, Max, and Team plans, as well as Enterprise customers, according to Anthropic. Pricing for Cowork itself was not addressed in this update, and Anthropic did not specify whether the browser feature carries any additional cost beyond existing subscription tiers.
What this means
This is a product feature update to Claude Cowork, not a new model release — the underlying Claude models are unchanged. The move reflects a broader push among AI agent products to handle real-world web tasks (form-filling, data extraction from non-API portals) without requiring users to expose their personal browsing session. The isolation approach — a sandboxed browser rather than direct access to a user's existing session — addresses a legitimate security concern: giving an autonomous agent unrestricted access to logged-in email or banking sessions would be a significant liability if prompt injection or misbehavior occurred. Excluding banking and email from credential transfer is a conservative but sensible limit given how immature prompt-injection defenses still are across the industry. Expect other agent products with browser-use capabilities to face similar tradeoffs between functionality and exposure to untrusted web content.
Related Articles
Anthropic CEO Dario Amodei Proposes Three-Step Plan to Deliberately Slow AI Capability Advances
Anthropic CEO Dario Amodei published an essay proposing a three-step plan to deliberately pace AI development, including third-party safety audits and cross-industry coordination. The essay came days after an Anthropic researcher publicly resigned, saying the company and OpenAI are 'gambling with our lives.'
Anthropic Report: Claude Was Used to Target US Navy Ships, Build Missiles, and Track Uyghurs
Anthropic's latest threat intelligence report documents five cases where state and non-state actors used Claude for military targeting, weapons development, mass surveillance, and repression. The findings include an Iran-linked operation targeting US naval forces and a Mali-based system capable of monitoring 25 million phones.
Augment Code Claims 4.5x Developer Output Increase From Internal 'Software Factory' of AI Agents
Augment Code says its internal 'software factory'—a network of specialized agents built on its Cosmos platform—drove a 4.5x increase in size-adjusted developer output and cut median PR merge time from 11.2 to 3.1 hours over nine months. The company frames this as evidence that once AI writes nearly all new code, the bottleneck shifts to review, verification, and incident response.
AWS Shows How to Build Interactive MCP Apps on Amazon Bedrock AgentCore
AWS published a technical walkthrough for building MCP Apps—interactive HTML widgets rendered inside AI hosts like ChatGPT and Claude—using Amazon Bedrock AgentCore's runtime and Gateway components. The reference implementation, a unicorn rental app, demonstrates host-agnostic rich UI delivered through a single MCP server.
Comments
Loading...