Back to News
ProductAI Understanding briefing

Anthropic makes Claude in Chrome generally available with autonomous browser actions

BigGo Finance reports that Anthropic has broadly released Claude in Chrome, allowing Claude to navigate webpages, enter text and fill forms with reduced approval prompts. The company says layered defenses cut attack success rates to 0–0.3% in its latest evaluations, though those results have not been independently…

By 5 min readRead the primary source
Source-provided image accompanying Anthropic makes Claude in Chrome generally available with autonomous browser actions
The short version

BigGo Finance reports that Anthropic has broadly released Claude in Chrome, allowing Claude to navigate webpages, enter text and fill forms with reduced approval prompts. The company says layered defenses cut attack success rates to 0–0.3% in its latest evaluations, though those results have not been independently…

What happened

BigGo Finance reports that Anthropic began general availability of Claude in Chrome on August 26. The browser extension lets Claude read the current webpage and perform actions such as clicking links, navigating, entering text and filling forms while retaining the user’s logged-in state. It is available on paid Claude plans, with enterprise domain restrictions, but Chrome is currently required and desktop-file or other-application tasks still require Anthropic’s desktop app.

BigGo Finance reports that Anthropic has moved Claude in Chrome from an approval-required browser assistant to general availability for users on paid Claude plans. After installation from the Chrome Web Store, Claude can read the webpage being displayed and carry out browser operations, including text entry, link clicks, page navigation and form completion. The source says the extension can preserve a user’s logged-in state, allowing it to work inside websites that do not have a native Claude integration.

The practical change is access to ordinary browser-based systems rather than only dedicated AI integrations. According to BigGo Finance, Claude in Chrome can interact with internal dashboards, legacy systems and vendor portals. The source says enterprise administrators can restrict the feature to approved domains through organizational settings. Chromium-based browsers other than Google Chrome and mobile environments are not currently supported, and tasks involving files on a computer or other applications still require Anthropic’s desktop app.

The central security issue is prompt injection: malicious instructions embedded in webpages or emails can attempt to redirect an AI agent away from the user’s request. BigGo Finance says Anthropic disclosed a 23.6% attack-success rate during the 2025 beta when no defenses were used. The company now combines model training on attack examples, probes that inspect webpage and email content, and classifiers that check proposed actions immediately before execution.

BigGo Finance reports that the latest evaluation produced attack-success rates of 0% for Claude Sonnet 5, Claude Opus 5 and Claude Mythos 5, and 0.3% for Claude Fable 5 when probes and classifiers were combined. It also reports rates of 17.6% for the previous-generation Claude Opus 4.5 and 3.8% for Claude Opus 5 without additional defenses in a newer, more powerful red-team evaluation. Anthropic says the successful attacks were low severity. These results are not independently confirmed in the supplied report.

Source details: finance.biggo.com

Why it matters

This is a meaningful shift from conversational AI toward software that can take actions inside existing websites, including legacy systems and vendor portals without native Claude integrations. The safety significance is substantial because webpages and emails can contain hidden instructions designed to redirect an agent. BigGo Finance reports sharp improvements in Anthropic’s tests, but the figures are company-reported and do not establish real-world safety.

Browser-operating AI could make existing software accessible through natural-language instructions without requiring every service to build a separate integration. That may reduce friction for repetitive administrative work, particularly where organizations rely on older web systems. It also changes the risk profile: an incorrect answer in a chat is different from an agent entering data, following a link or submitting a form under a user’s authenticated session.

Prompt injection is difficult because the agent must distinguish the user’s instructions from hostile content encountered during browsing. The three-layer approach described by BigGo Finance addresses different points in that process: training aims to improve the model’s resistance, probes inspect content before action, and classifiers compare an intended action with the original request. The layered design is consequential, but the source provides no independent audit, methodology, sample sizes or reproducible test materials.

The reported results should therefore be read as evaluation evidence rather than a guarantee of safe autonomous operation. Attackers can change their wording and delivery methods, and real websites may contain unexpected content, permissions or workflows not represented in controlled tests. The source says Anthropic is using automated attack discovery, external red teams and real-world monitoring, but it does not establish how broadly those systems cover the websites, languages, account types or high-impact tasks that users may encounter.

The feature’s restrictions also define its near-term public impact. Chrome-only support and the continued need for the desktop app for local files or other applications limit the range of tasks Claude can perform. At the same time, domain controls could give enterprises a way to narrow exposure. BigGo Finance’s separate account of Claude Code limits shows that product availability and usage capacity are changing together, although the report does not provide usage data linking those changes to customer demand or safety considerations.

What to watch next

The key questions are whether Claude in Chrome remains reliable against changing prompt-injection techniques, how often users are asked for confirmation, and how enterprise administrators use domain restrictions. Availability, browser support and the limits of the reported evaluations also matter. BigGo Finance separately reports that Anthropic will change Claude Code usage limits on September 14, ending a temporary 50% increase while making a 25% increase permanent.

The first issue to watch is how Anthropic handles actions that are difficult to reverse, such as submitting forms, changing account settings or entering sensitive information. BigGo Finance says users can retain manual approval workflows, and that potential attacks may trigger a confirmation request. The report does not specify which actions are always blocked, which are automatically approved, or whether safeguards vary by plan, domain or task type.

Independent testing would help clarify whether the reported 0–0.3% attack-success rates generalize beyond Anthropic’s evaluation environment. Important unknowns include the exact attack corpus, the definition of success, the severity distribution, the number of trials, the treatment of partial compromise and performance against previously unseen attacks. The source says Anthropic retired its earlier evaluation suite because current models defeated it, then moved to stronger red-team attacks; that change makes comparisons over time difficult.

Enterprise buyers will likely need to examine domain restrictions, audit logs, permission boundaries and data-handling rules before enabling autonomous browser actions. The supplied report confirms domain controls but does not explain whether organizations can limit specific action types, review every completed action, or separate read access from write access. It also does not say how Claude behaves when a webpage changes after an action is approved or when a workflow crosses multiple domains.

BigGo Finance separately reports that Anthropic will permanently raise standard weekly Claude Code limits by 25% on Pro, Max, Team and seat-based Enterprise plans beginning September 14, while ending a temporary 50% increase. The source describes user criticism because the permanent level is lower than the temporary one. That change is not the same event as Claude in Chrome, but it is a relevant product-policy development to monitor alongside the broader expansion of Anthropic’s agent capabilities.

Related guides & quizzes

AI AgentsAI EthicsPrompt EngineeringChatGPT & LLMsTest what you know — try a free AI quizLook up an AI term in our glossary
Found this useful?