Anthropic expanded Claude from a chat assistant into an agent that can take actions in external services, adding live Gmail and Google Drive operations as well as a new Browser Use API tool for structured web interaction. Claude can now send, reply to, and forward Gmail messages and modify files in connected Google Drive accounts using a user’s existing Google authentication and inherited Workspace permissions; Anthropic said write actions require user approval by default and that Gmail, Drive, and Calendar connector data is not used to train models, though retrieved connector data is stored with chats on its servers.
The company also released Browser Use alongside general availability for Computer Use, the Skills API, and the Files API, giving developers a way to let Claude interact with web pages through accessibility-tree element references rather than screen coordinates. Anthropic and outside reporting warned that these capabilities raise security risks including prompt injection, parsing mistakes, unexpected navigation, and overly permissive approval settings that could result in outbound emails, altered sharing permissions, moved folders, deleted files, or unsafe browser actions; recommended mitigations include running agents in isolated containers or virtual machines, minimizing privileges, and disabling JavaScript or file uploads unless required.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Anthropic announced Browser Use on Thursday, introducing a Claude API tool that uses a page's accessibility tree so Claude can interact with web elements by structured references rather than screen coordinates. The same broader release also made Computer Use, the Skills API, and the Files API generally available.
On August 18, 2026, Anthropic announced that Claude can now perform live write actions in connected Google accounts, including sending, replying to, and forwarding Gmail messages and sharing, moving, and trashing files in Google Drive. This expanded Claude from draft-only assistance to action-capable operations using the user's Google identity, with approval enabled by default for write actions.
Anthropic's pricing documentation states that the default Browser Use toolset adds roughly 6,600 input tokens to a request before screenshots, accessibility trees, and other results. This documentation is cited as part of the Browser Use release coverage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
thenewstack.io
Open sourcecybersecuritynews.com
Open sourceplatform.claude.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.