Anthropic’s Chrome extension is now a Cowork session
The New Stack Frederic Lardinois
Anthropic turned Claude in Chrome into a real Cowork session. Your chats, skills, and connectors now follow you across Claude apps—and the browser agent still carries prompt-injection risk.
Based on reporting by The New Stack, Frederic Lardinois — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Anthropic has given its Chrome extension a much deeper role. Claude in Chrome is no longer a mostly isolated browser tool; it now works as a full Claude Cowork client, with sessions that carry across Anthropic’s apps instead of stopping at the browser tab.
That change is rolling out now to Max and Team subscribers, with Pro users set to get access in the coming weeks. It also fixes one of the extension’s biggest complaints: conversations are saved in the user’s history, so a thread can start on desktop or mobile and continue in Chrome without friction. The same goes for skills and connectors, which now show up in the Chrome sidebar too.
The pitch is pretty simple. Claude can see the page the user is on and act inside web apps that don’t connect directly, including internal dashboards, legacy systems, and vendor portals. That makes the browser extension feel much less like a side feature and much more like part of the core product.
Anthropic’s broader Cowork push seems to be setting the default here. Cowork only came to the web and mobile a few weeks ago, and before that it lived in the desktop app. Now the browser version is in the same family, which also raises the obvious question of whether basic Claude chat will eventually be folded into it.
Safety is still the catch. Anthropic says the browser agent faces the same prompt-injection risks as any AI that acts inside a webpage, and its auto mode now extends into Chrome so the system can look for anything strange without forcing constant approvals. It will still ask before purchases or sharing personal data, and enterprise admins can keep it off by default, enable it, or restrict it to specific domains. The extension does not run on other Chromium-based browsers or on mobile.
My take — AI-written commentary, not fact-checked reporting
Anthropic is making the right call here: if a browser agent can’t share context, it’s just a fancy sidecar. The bigger story is that AI companies keep treating browser access like a product feature when it’s really a security headache with a nicer UI. The prompt-injection warning is not a footnote; it’s the whole show.
Read more about this at: The New Stack