Anthropic has upgraded its Claude in Chrome extension into a full Claude Cowork client, adding persistent sessions that carry browser conversations into a user’s Claude history and exposing saved skills and connectors directly in the Chrome sidebar. The company said the extension is designed to let users continue work across desktop, mobile, and browser environments, including browser-based internal dashboards, legacy systems, and vendor portals that do not natively integrate with Claude.
Anthropic said prompt injection remains the primary security risk for browser-based AI agents and tied the rollout to its published research on browser-use prompt-injection defenses. The company said it has extended Claude auto-mode protections to the extension, while still requiring explicit user approval for sensitive actions such as purchases or sharing personal data. The feature is available now for Max and Team subscribers, will reach Pro users in coming weeks, and is disabled by default for Enterprise deployments unless administrators enable it and can optionally limit use to specific domains.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Anthropic announced a major update to its Claude in Chrome extension that turns it into a full Claude Cowork client with persistent sessions across Anthropic apps. The update also brings saved browser conversations, skills and connectors in the Chrome sidebar, and availability for Max and Team subscribers.
Anthropic published research on mitigating prompt injection risks in browser use, the security issue it later described as the chief risk for browser-based AI agents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.