Anthropic is rolling out a Chromium-based browser inside Claude Cowork, giving paid users a separate environment for research and other web-based tasks.
Anthropic has added a built-in web browser to the Claude Cowork desktop app, allowing the AI assistant to browse websites directly without relying on the Claude in Chrome extension for many tasks.
The new browser is rolling out to paid Claude Pro, Max and Team subscribers on Mac, Windows and Linux. Based on Chromium, it operates within Cowork and is designed to let users ask Claude to perform web-based tasks while remaining inside the desktop application.
Previously, users who wanted Claude to interact with webpages often needed the Claude in Chrome extension. The extension allows Claude to work with pages already open in the user’s browser, including websites where the user is signed in.
Anthropic’s built-in browser is intended for tasks that do not require access to an existing browser session. Claude can use it to open websites, research information and carry out other online tasks in a separate browsing environment.
The company describes the distinction as “Claude’s browser, not yours,” highlighting that the built-in browser is separate from the user’s regular browser. It does not automatically inherit accounts or login sessions stored in the user’s everyday browser.
The Chrome extension will continue to have an important role. It remains useful when users want Claude to work with an existing webpage or interact with services where they are already logged in. Anthropic’s support documentation also confirms that Claude can interact with browser content through Claude in Chrome, including pages behind a login.
Anthropic also allows users to transfer certain login information into the built-in browser. On macOS, supported imports include Chrome, Edge and Firefox, while Firefox is supported on Windows and Linux. Banking, email and single sign-on accounts are excluded by default, requiring users to deliberately provide access.
The separation is also intended to reduce security risks. Web-enabled AI agents can be exposed to prompt injection attacks, in which malicious instructions are embedded in webpages and attempt to influence the AI’s behavior. Anthropic has acknowledged prompt injection as a significant risk associated with browser and computer-use capabilities.













