Productspublished

Claude Cowork Adds a Separate Browser, but Prompt-Injection Risk Remains

The in-app browser gives Claude a more limited starting point for web work and selected logins, while hostile instructions embedded in webpages can still try to redirect the agent.

By 3 min read
Claude Cowork Adds a Separate Browser, but Prompt-Injection Risk Remains

Listen to this story

The audio brief

About 1:23
0:001:23
Read transcript
Claude Cowork can now open a separate browser inside its desktop app, instead of operating through the browser you already have open. Anthropic says that creates a narrower boundary: by default, Cowork cannot see your personal tabs, bookmarks, or saved passwords. That makes web-based assignments less exposed to the rest of your browsing life, but it does not make the agent safe from hostile webpages. Cowork uses its own browser when Claude in Chrome is unavailable, and users can change that preference in Settings. For authenticated tasks, people can deliberately share credentials from Chrome, Edge, or Firefox for a selected site. Banking, email, and single sign-on accounts stay excluded unless the user explicitly includes them. The important limitation is prompt injection. Instructions hidden inside a webpage can still try to redirect Claude’s actions, even though the browser is separated from personal data. Anthropic says the built-in browser has the same safeguards as Claude in Chrome and recommends starting with trusted sites. The feature is rolling out to Pro, Max, and Team subscribers on macOS and Windows, with a Linux beta. Web and mobile sessions can continue after the desktop app closes, but they lose access to local files, connectors, and computer control. The thing to watch is whether this narrower browser boundary is enough when the page itself is trying to steer the agent.

Story brief

3 key points

Anthropic is expanding Claude Cowork’s web capabilities with an isolated browser for Pro, Max, and Team subscribers on macOS and Windows, plus a Linux beta. The separation limits exposure to personal tabs, bookmarks, and saved passwords, while still allowing users to grant selected site credentials. It does not solve prompt injection: hostile webpage instructions can still redirect the agent. Cowork therefore offers...

  1. 01

    The browser is rolling out on macOS and Windows, with a Linux beta, for Pro, Max, and Team subscribers.

  2. 02

    Banking, email, and single sign-on credentials remain excluded unless users deliberately share them for a site.

  3. 03

    Cowork uses its browser when Claude in Chrome is unavailable; users can change the preference in Settings.

Claude Cowork can now open a separate browser inside its desktop app, rather than working through a user’s active browser session. Anthropic says that browser cannot access personal tabs, bookmarks, or saved passwords by default—a meaningful boundary for web tasks, but not a cure for malicious content on the web.

A browser for the task, not the whole browsing life

The browser runs in Cowork’s desktop side panel and handles web portions of a task without using the browser session already open on the computer. That is a different route from Claude in Chrome, which works in the user’s existing browser environment. When Claude in Chrome is already in use, it remains the default; otherwise, Cowork uses its own browser automatically, and the preference can be changed in Settings.

Credentials are selective; webpage instructions are not harmless

Separation does not prevent authenticated work. Users can choose to share logins from Chrome, Edge, or Firefox for particular sites. Banking, email, and single sign-on accounts are excluded by default unless the user deliberately includes them.

The permission boundary

  • Personal browser tabs, bookmarks, and saved passwords stay unavailable by default.
  • A user may share a login for a chosen site from Chrome, Edge, or Firefox.
  • Banking, email, and single sign-on accounts require a deliberate opt-in to be shared.

Anthropic says malicious instructions hidden in a webpage can still attempt to hijack Claude’s actions through prompt injection. The company says the built-in browser uses the same safeguards as Claude in Chrome and recommends beginning with trusted sites. The key limit is straightforward: a narrower set of browser data does not stop an agent from encountering hostile instructions on a page it is asked to visit.

Wide paid access, with desktop still carrying the local work

The desktop browser is rolling out to Pro, Max, and Team subscribers on macOS and Windows, with a Linux beta. Cowork is also available on web and mobile for Pro, Max, and Team users; Enterprise access on those surfaces requires administrator enablement. Anthropic’s documentation still labels web and mobile Cowork as beta.

Sessions and files can move between desktop, web, and mobile because they are attached to the user’s Claude account. But local folders, local connectors, browser control, and computer use still require Claude Desktop on the connected computer. A cloud task can continue if that app closes, though it loses access to that device.

Cowork is designed for assignments involving connected files, email, calendars, messaging apps, the web, and other tools. The new browser gives those assignments a more bounded web option, while leaving users to decide which sites and credentials warrant delegated access.

Sources

  1. digitaltrends.comClaude Cowork gets its own browser that doesn’t touch your tabs, bookmarks, or saved passwords