Anthropic updated Claude Cowork and Claude Code to let their computer-use capability operate applications in background windows through the Claude Desktop app, allowing users to continue working in the foreground. The feature is available on macOS and Windows, although background execution is currently restricted to macOS 15 or later and is disabled by default.
Claude preferentially uses native service connectors and browser-based workflows before resorting to direct screen interaction. Anthropic cautions that screen-level control does not provide the isolation of sandboxed code execution or permissioned file access, increasing exposure to malicious prompt injection and social-engineering attacks; organizations should treat the capability as privileged automation and enforce scoped access, monitoring, and deployment governance.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Anthropic introduced the underlying computer-use capability through its developer API in late 2023.
Anthropic added background execution for computer use, allowing Claude to click, type, open applications, and complete desktop tasks in background windows while users continue foreground work. The feature is delivered through Claude Desktop for macOS and Windows, is disabled by default, and background execution is currently limited to Macs running macOS 15 or later.
Anthropic later made computer use available to Claude Cowork and Claude Code users with Pro and Max subscriptions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.