Claude Gets Its Own Browser in Cowork
Cowork can now open and operate a separate browser inside the desktop app, reducing setup and exposure to your personal browser while prompt-injection risk remains despite safeguards.
The 60-second version
Claude Cowork now operates a separate built-in browser for web tasks inside the desktop app.
Key points
- It can navigate, read, click, type, and use portals without a browser extension.
- It does not automatically expose a user's personal tabs, bookmarks, or passwords.
- Claude in Chrome remains the better choice for pages and sessions already open in the user's own browser.
- Pro, Max, and Team rollout begins this week; Enterprise administrators can enable it now.
- Prompt injection remains possible, so trusted sites and human review still matter.
Verdict. This is a meaningful compartmentalization upgrade, but not permission to give a browser agent unrestricted access to sensitive accounts.
Claude Cowork can now open and operate a browser of its own inside the desktop app. The change removes the extension requirement for many web tasks and keeps the agent separate from a user's personal browser by default.
What shippedA browser for the agent, not the user
When a Cowork task needs a website, a browser can open in a side panel. Claude can navigate pages, read content, click controls, type into forms, pull figures from dashboards, and work through portals that do not have a connector.
The built-in browser is separate from the browser a person uses every day. Anthropic says Claude does not automatically see personal tabs, bookmarks, or passwords. That makes the default exposure smaller than handing an agent an already authenticated personal session.
Choose the modeBuilt-in browser versus Claude in Chrome
| Built-in browser | Best for self-contained web tasks that can be handed off, such as gathering research or collecting invoices from a portal. |
|---|---|
| Claude in Chrome | Best when Claude must work in the exact page, account session, inbox, CRM, or document already open in the user's browser. |
| Default behavior | Existing Claude in Chrome users keep it as the default; everyone else uses the built-in browser and can switch in Cowork settings. |
Selected logins can be imported site by site from Chrome, Edge, or Firefox on macOS, and from Firefox on Windows and Linux. Banking, email, and single sign-on sites are omitted unless the user explicitly includes them.
The useful security improvement is compartmentalization, not immunity.
Security boundaryPrompt injection remains the hard problem
Untrusted web content can contain hidden or misleading instructions aimed at an AI agent. The attack surface includes pages, embedded documents, advertisements, and dynamically loaded scripts; browser use makes that dangerous because the same agent may also be able to click, type, download files, or submit data.
Anthropic says the built-in browser uses the same safeguards as Claude in Chrome, including checks that compare actions with the user's request. Its own announcement is explicit that these controls cannot eliminate the risk.
- 1. Start with trusted, low-consequence websites.
- 2. Import only the login needed for the current workflow.
- 3. Review purchases, messages, uploads, submissions, and permission changes before completion.
- 4. Keep banking, primary email, and identity-provider sessions separate until there is a compelling need.
AvailabilityWho gets it and where it runs
| Pro, Max, Team | Rolling out during the week of August 26 in the Claude desktop app. |
|---|---|
| Enterprise | Available now for administrators to enable and manage in organization settings. |
| Platforms | macOS, Windows, and Linux desktop apps; the feature is in beta. |
| Remote direction | Claude on the web or phone can drive the built-in browser while the desktop app remains open and online. |
Bottom lineWeb delegation becomes easier, not risk-free
The built-in browser gives Cowork a cleaner way to handle routine web workflows without opening a user's entire browsing context. Use it for bounded tasks, grant the minimum access required, and keep a human checkpoint around consequential actions.