Claude in Chrome goes generally available and starts acting without asking, and Claude gets a second browser of its own
Anthropic published two posts on 26th Aug that together change what Claude does on other people's websites.
The first says Claude in Chrome is generally available. Plan coverage reached every paid plan in December 2025, so that is not the change that matters.
It is that "Claude can now also take actions autonomously in the browser, instead of needing approval for every one", using the same automatic-approval mechanism as Claude Code.
A classifier reviews each action Claude is about to take. That includes opening a site or typing into a page.
It blocks any action that does not match what the user asked for. The setting can be switched off.
What Claude does through the extension is unchanged in kind. It reads the page, clicks links, types text, navigates and fills forms, on the user's existing logins.
The second post is the new one. Claude now has its own browser inside the Claude Cowork desktop app.
It opens in a side panel. It does the same navigating, reading, clicking and typing without touching the user's own browser at all.
Anthropic's framing of why both exist: "a lot of web tasks don't need your browser, just a browser, and now Claude has one".
Logins are carried over site by site from Chrome, Edge or Firefox. Banking, email and single sign-on sites are excluded unless the user opts them in.
It is rolling out over the week to Pro, Max and Team on macOS, Windows and Linux. It is on by default once it arrives.
Enterprise has it now, managed by admins in organization settings. Those admins can also restrict Claude in Chrome to approved domains.
The extension does not run on other Chromium browsers or on mobile.
For a site owner, what matters is what none of this appears in.
Anthropic's site-owner help page describes three bots and states that they honour robots.txt. They are ClaudeBot for training, Claude-User for fetches triggered by a user's question and Claude-SearchBot for search quality.
Read on 27th Aug, that page does not contain the words browser, Chrome, extension or agent anywhere. Neither of the two announcements names a user agent.
So there is no published way for a site owner to recognise this traffic. There is also no stated answer to whether robots.txt bears on it at all.
That is a different situation from a crawler you can allow or refuse. Requests arrive inside a signed-in session that the user authorised.
That is the same shape as Grok Bot. It is the reason this hub keeps returning to the gap between crawler controls and agent traffic.
The prompt-injection numbers are published, and they are the most detailed on this beat.
Anthropic's current test set is built from attacks written by professional red-teamers. Attacks that reached the model succeeded 17.6% of the time against Opus 4.5 before extra safeguards.
Against Opus 5 the rate was 3.8%. Anthropic also reports results with the content probes and the approval classifier running.
There were no successful attacks against Sonnet 5, Opus 5 or Mythos 5. Fable 5 saw a 0.3% success rate.
Two caveats come from Anthropic itself. The older test set was retired because it had been saturated at a 0% success rate.
Not every attack reaches the model in the first place. So these rates describe the attacks that got through rather than all attempts.
Anthropic's own conclusion is the one to carry into any decision about letting agents onto a site. The measures "meaningfully reduce the risk but can't eliminate it", and it recommends starting on sites the user trusts.