返回新闻
产品展示AI Understanding 简报

Anthropic 使 Chrome 中的 Claude 通常可通过自主浏览器操作使用

BigGo Finance 报道称,Anthropic 已在 Chrome 中广泛发布了 Claude,允许 Claude 浏览网页、输入文本和填写表单,同时减少审批提示。该公司表示,在其最新评估中,分层防御将攻击成功率降低至 0-0.3%,尽管这些结果并未独立得出……

5 min readRead the linked source
Source-provided image accompanying Anthropic makes Claude in Chrome generally available with autonomous browser actions
来源参考来源记录
出版商
finance.biggo.com
来源链接
finance.biggo.comhttps://finance.biggo.com/news/04bd1c2f-2660-4a13-8067-472a7c776690
来源类型
链接来源——主要来源状态尚未确定。
背景60 秒内了解这一点

从这里开始

关键术语

及时注射
一种攻击模式,其中恶意指令被插入到模型输入或检索的内容中。
人工智能代理
一种可以观察、推理并采取行动来实现目标的软件系统,通常使用工具和内存。
特征
模型用来进行预测的输入变量。
测试一下自己AI 代理测验

发生了什么

BigGo Finance reports that Anthropic began general availability of Claude in Chrome on August 26. The browser extension lets Claude read the current webpage and perform actions such as clicking links, navigating, entering text and filling forms while retaining the user’s logged-in state. It is available on paid Claude plans, with enterprise domain restrictions, but Chrome is currently required and desktop-file or other-application tasks still require Anthropic’s desktop app.

BigGo Finance reports that Anthropic has moved Claude in Chrome from an approval-required browser assistant to general availability for users on paid Claude plans. After installation from the Chrome Web Store, Claude can read the webpage being displayed and carry out browser operations, including text entry, link clicks, page navigation and form completion. The source says the extension can preserve a user’s logged-in state, allowing it to work inside websites that do not have a native Claude integration.

The practical change is access to ordinary browser-based systems rather than only dedicated AI integrations. According to BigGo Finance, Claude in Chrome can interact with internal dashboards, legacy systems and vendor portals. The source says enterprise administrators can restrict the to approved domains through organizational settings. Chromium-based browsers other than Google Chrome and mobile environments are not currently supported, and tasks involving files on a computer or other applications still require Anthropic’s desktop app.

The central security issue is : malicious instructions embedded in webpages or emails can attempt to redirect an away from the user’s request. BigGo Finance says Anthropic disclosed a 23.6% attack-success rate during the 2025 beta when no defenses were used. The company now combines model training on attack examples, probes that inspect webpage and email content, and classifiers that check proposed actions immediately before execution.

BigGo Finance reports that the latest evaluation produced attack-success rates of 0% for Claude Sonnet 5, Claude Opus 5 and Claude Mythos 5, and 0.3% for Claude Fable 5 when probes and classifiers were combined. It also reports rates of 17.6% for the previous-generation Claude Opus 4.5 and 3.8% for Claude Opus 5 without additional defenses in a newer, more powerful red-team evaluation. Anthropic says the successful attacks were low severity. These results are not independently confirmed in the supplied report.

来源详情: finance.biggo.com ↗

为什么这很重要

This is a meaningful shift from conversational AI toward software that can take actions inside existing websites, including legacy systems and vendor portals without native Claude integrations. The safety significance is substantial because webpages and emails can contain hidden instructions designed to redirect an agent. BigGo Finance reports sharp improvements in Anthropic’s tests, but the figures are company-reported and do not establish real-world safety.

Browser-operating AI could make existing software accessible through natural-language instructions without requiring every service to build a separate integration. That may reduce friction for repetitive administrative work, particularly where organizations rely on older web systems. It also changes the risk profile: an incorrect answer in a chat is different from an agent entering data, following a link or submitting a form under a user’s authenticated session.

is difficult because the agent must distinguish the user’s instructions from hostile content encountered during browsing. The three-layer approach described by BigGo Finance addresses different points in that process: training aims to improve the model’s resistance, probes inspect content before action, and classifiers compare an intended action with the original request. The layered design is consequential, but the source provides no independent audit, methodology, sample sizes or reproducible test materials.

The reported results should therefore be read as evaluation evidence rather than a guarantee of safe autonomous operation. Attackers can change their wording and delivery methods, and real websites may contain unexpected content, permissions or workflows not represented in controlled tests. The source says Anthropic is using automated attack discovery, external red teams and real-world monitoring, but it does not establish how broadly those systems cover the websites, languages, account types or high-impact tasks that users may encounter.

The ’s restrictions also define its near-term public impact. Chrome-only support and the continued need for the desktop app for local files or other applications limit the range of tasks Claude can perform. At the same time, domain controls could give enterprises a way to narrow exposure. BigGo Finance’s separate account of Claude Code limits shows that product availability and usage capacity are changing together, although the report does not provide usage data linking those changes to customer demand or safety considerations.

Interactive Mechanism

互动机制:它实际上是如何运作的

以交互方式探索这一发展背后的基础技术。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
交互式概念检查+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

接下来看什么

The key questions are whether Claude in Chrome remains reliable against changing prompt-injection techniques, how often users are asked for confirmation, and how enterprise administrators use domain restrictions. Availability, browser support and the limits of the reported evaluations also matter. BigGo Finance separately reports that Anthropic will change Claude Code usage limits on September 14, ending a temporary 50% increase while making a 25% increase permanent.

The first issue to watch is how Anthropic handles actions that are difficult to reverse, such as submitting forms, changing account settings or entering sensitive information. BigGo Finance says users can retain manual approval workflows, and that potential attacks may trigger a confirmation request. The report does not specify which actions are always blocked, which are automatically approved, or whether safeguards vary by plan, domain or task type.

Independent testing would help clarify whether the reported 0–0.3% attack-success rates generalize beyond Anthropic’s evaluation environment. Important unknowns include the exact attack corpus, the definition of success, the severity distribution, the number of trials, the treatment of partial compromise and performance against previously unseen attacks. The source says Anthropic retired its earlier evaluation suite because current models defeated it, then moved to stronger red-team attacks; that change makes comparisons over time difficult.

Enterprise buyers will likely need to examine domain restrictions, audit logs, permission boundaries and data-handling rules before enabling autonomous browser actions. The supplied report confirms domain controls but does not explain whether organizations can limit specific action types, review every completed action, or separate read access from write access. It also does not say how Claude behaves when a webpage changes after an action is approved or when a workflow crosses multiple domains.

BigGo Finance separately reports that Anthropic will permanently raise standard weekly Claude Code limits by 25% on Pro, Max, Team and seat-based Enterprise plans beginning September 14, while ending a temporary 50% increase. The source describes user criticism because the permanent level is lower than the temporary one. That change is not the same event as Claude in Chrome, but it is a relevant product-policy development to monitor alongside the broader expansion of Anthropic’s agent capabilities.

相关指南和测验

人工智能代理AI 伦理Prompt EngineeringChatGPT 与大语言模型测试你所知道的——尝试免费的人工智能测验在我们的词汇表中查找人工智能术语关注 AI 模型发布跟踪器
觉得这有用吗?