Claude Adds Built-In Browser to Cowork, Enabling Autonomous Task Completion

Anthropic announced today that it has integrated a full browser into Claude Cowork’s side panel. When a task involves a website, a browser opens in Cowork’s side panel, and Claude navigates, fills forms, and finishes the job.

The feature is available immediately for Max and Team subscribers, with Pro tier access rolling out in the coming weeks. Enterprise administrators can enable the feature and restrict Claude’s browser access to a whitelist of approved domains.

Claude Cowork Browser

Claude can now interact with websites where users are already logged in, extract data from vendor portals, fill out forms across multiple pages, and complete web-based tasks autonomously within the extension.

How Browser Tasks Work in Cowork

When a user assigns Claude a task involving a website, Cowork opens a browser panel. Claude observes the current webpage, clicks links, fills input fields, scrolls, and extracts text to complete the task autonomously. A practical example from Anthropic involves asking Claude to collect invoice details from several vendor portals and compile them into a spreadsheet. The full context of what Claude accomplishes in the browser is retained within the session.

Security and Prompt Injection Risk

Browser agents remain vulnerable to prompt injection attacks, where malicious code embedded in a website can trick Claude into executing unintended actions. Anthropic has layered safeguards to mitigate the risk: a separate check reviews consequential actions when automatic approval is enabled, and Claude still requests permission before executing sensitive operations such as purchases or sharing personal data. The company states these safeguards reduce risk but cannot eliminate it entirely.

Prompt injection attacks work by embedding hidden instructions in web pages; if Claude navigates to a malicious or compromised site, it could be tricked into actions a user did not intend. Anthropic’s safeguard layer addresses this by flagging actions that modify accounts, move money, or share sensitive information, requiring explicit user approval before proceeding. However, the company acknowledges that no set of checks can eliminate the risk entirely, particularly as attackers develop more sophisticated injection techniques.

Availability and Rollout

The built-in browser is rolling out over the coming week to Pro, Max, and Team plans in the Claude desktop app on macOS, Windows, and Linux (in beta).

On Enterprise plans, it’s available now and admins can manage it by going to Organization settings > Cowork > Built-in browser.

Newsletter
Never miss an Apple story
One email a day, the news that matters. No spam, unsubscribe anytime.
About the Author

Imran Hussain is the founder and editor of iThinkDifferent, which he launched in 2008 to cover Apple news, reviews, and how-to guides. He has spent over 15 years writing about iOS, macOS, and the wider Apple ecosystem, with a focus on hands-on guides - installing developer betas, troubleshooting, and walking through new features on his own devices. Based in Dubai, he also loves to cover photography, gaming, and the tech industry more broadly on his social media profiles.

Leave a Reply