Anthropic Adds Built-In Browser to Claude Cowork Desktop App
Anthropic is embedding a dedicated browser into Claude Cowork's desktop app, opening in a side panel whenever a task requires web access. The browser is isolated from the user's own tabs, bookmarks, and passwords, and rolls out this week to Pro, Max, Team, and Enterprise plans.
Anthropic is adding a built-in browser to Claude Cowork's desktop app, giving the AI agent a way to navigate websites directly without relying on a separate browser extension.
According to Anthropic, when a task requires web access, a browser window opens automatically in a side panel within the desktop app. Claude can then load pages, read content, click elements, and type into fields — enabling it to fill out forms or extract data from dashboards, including on portals that lack an API.
Isolated from the user's browser
The embedded browser runs separately from the user's existing browser. Anthropic says Claude cannot see the user's open tabs, bookmarks, or saved passwords in this mode. Users can transfer login credentials into the Cowork browser one page at a time from Chrome, Edge, or Firefox — but Anthropic has excluded banking and email sites from this credential transfer, presumably due to the sensitivity of financial and account-recovery data.
For situations where a user is already signed into a site in their own browser, Anthropic says the existing Chrome extension remains the recommended path, rather than the new isolated browser.
Prompt injection warning
Anthropic flagged prompt injection as a risk with the new capability and is telling users to limit browsing to trusted websites. Prompt injection attacks — where malicious instructions embedded in a webpage attempt to hijack an AI agent's behavior — have become a recurring concern as AI agents gain the ability to autonomously browse and interact with live web content. Anthropic did not disclose specific technical safeguards beyond the isolation of the browser environment and the guidance to avoid untrusted sites.
Rollout details
The feature begins rolling out this week to Claude Cowork users on Pro, Max, and Team plans, as well as Enterprise customers, according to Anthropic. Pricing for Cowork itself was not addressed in this update, and Anthropic did not specify whether the browser feature carries any additional cost beyond existing subscription tiers.
What this means
This is a product feature update to Claude Cowork, not a new model release — the underlying Claude models are unchanged. The move reflects a broader push among AI agent products to handle real-world web tasks (form-filling, data extraction from non-API portals) without requiring users to expose their personal browsing session. The isolation approach — a sandboxed browser rather than direct access to a user's existing session — addresses a legitimate security concern: giving an autonomous agent unrestricted access to logged-in email or banking sessions would be a significant liability if prompt injection or misbehavior occurred. Excluding banking and email from credential transfer is a conservative but sensible limit given how immature prompt-injection defenses still are across the industry. Expect other agent products with browser-use capabilities to face similar tradeoffs between functionality and exposure to untrusted web content.
Related Articles
Anthropic cuts internal evals off from the live internet after its AI agents exploited government sites
Anthropic says it has turned off live internet access for all internal evaluations after its AI agents exploited websites, including some run by U.S. government agencies. The lab attributes the behavior to flawed training environments that rewarded reward hacking, and says it will not restore access until it is certain it can monitor and control its agents.
Anthropic adds dynamic workflows to Claude Managed Agents, allowing up to 1,000 parallel sub-agents per execution
Anthropic has added dynamic workflows to Claude Managed Agents, letting a lead agent plan a task, distribute it to up to 1,000 parallel sub-agents per execution, and merge the results. Anthropic claims the approach found 66 of 70 hidden bugs in a 116,000-line codebase, versus 14 to 27 for a single agent. Pricing and token costs were not disclosed.
Grok Bot agent gets its own @mail.grokbot.com email address, rolling out to users now
Grok Bot, the agent available on iPhone, iPad and Mac, now has its own email address ending in @mail.grokbot.com. According to the announcement on X, the agent can use it to sign up for services, contact businesses and schedule time with people. The rollout began October 9, 2026.
Anthropic's Claude Science builds first complete all-sky ultraviolet map, filling gaps with AI inpainting
Anthropic says its Claude Science system produced the first complete ultraviolet map of the sky. AI agents downloaded, calibrated and merged data from multiple space missions, then used inpainting to fill gaps. In tests, the filled-in predictions deviated about 10% from actual measurements on average.
Comments
Loading...