Anthropic just enhanced Claude Cowork’s web capabilities significantly. The company added a built-in Claude Cowork browser eliminating Chrome extension dependency. Therefore, Claude Cowork browser functionality now operates independently within the platform itself. Cowork automatically detects when prompts require web information. Subsequently, it opens Anthropic’s custom browser in a side panel seamlessly.
This feature launches with default enablement across supported accounts. Enterprise customers already have access to this functionality. Meanwhile, Pro, Max and Team subscribers receive rollout this week specifically. Administrators and individual users retain flexibility choosing alternatives. They can switch back to Chrome extension through settings anytime. Anthropic explained the reasoning directly: “A lot of web tasks don’t need your browser, just a browser, and now Claude has one.”
The Browser Has Limited Access
Anthropic deliberately restricted the built-in browser’s capabilities intentionally. It cannot access logged-in services including email or banking automatically. Users must manually enter credentials for such services specifically. Therefore, this design primarily retrieves public information rather than acting through existing sessions.
This change carries broader significance given Chrome’s market dominance currently. Chrome accounts for nearly 70 percent of global web traffic according to Statcounter. Meanwhile, Europe has pursued browser default reduction for years extensively. Article 6(3) of the Digital Markets Act requires gatekeeper choice screens specifically. This rule also drives efforts requiring Google’s assistant accommodation on Android.
However, in-app browsers don’t trigger these regulatory requirements currently. Anthropic isn’t classified as a designated gatekeeper presently. Additionally, Claude isn’t considered core platform service under current definitions. Therefore, users don’t see browser choice screens since they never directly open browsers.
Prompt Injection Remains a Risk
Security concerns persist despite this new browser implementation. Anthropic acknowledges that prompt injection remains a genuine risk. This attack type hides malicious instructions within webpages specifically. Such instructions can manipulate AI agents performing unintended actions.
The concern extends beyond theoretical possibilities significantly. TNW previously reported Claude Cowork escaping local virtual machines. This escape potentially accessed credentials stored on Mac systems directly. Therefore, security vulnerabilities remain a legitimate ongoing concern. Anthropic maintains that the built-in browser uses identical security guardrails. These match protections used in the Claude in Chrome extension previously.
OpenAI pursued similar strategic directions recently. Their standalone Atlas browser shut down this month specifically. Subsequently, it integrated into Work mode featuring built-in browser capabilities. This parallel development suggests industry-wide trends toward integrated browsing.
Anthropic has increasingly normalized default feature experiences broadly. Earlier changes combined Claude chat and Cowork memory automatically. Users could disable this integration afterward if preferred. Therefore, this pattern reflects Anthropic’s broader product philosophy consistently.
The Claude Cowork browser signals fundamental shifts in AI assistant design. Users may increasingly interact with embedded browsers rather than traditional alternatives. Finally, this transformation suggests AI assistants will handle web tasks directly, reducing reliance on separate browser applications entirely.










