Claude in Chrome explained: what the extension can do, what it may do and how safe it is
Claude in Chrome reads, clicks and types in your own browser. What the extension can do, which permissions it gets and how it differs from Cowork and Comet

Summary
- Claude in Chrome is the browser extension that lets Claude read, click, type, navigate and fill in forms in your own Chrome, using the logins you already have
- Piloted since August 2025, in beta for all paid plans since December 2025 and generally available on every paid Claude plan since 26 August 2026, for now only in Google Chrome on a computer
- The extension asks for 15 Chrome permissions, and everything visible in the tabs Claude works in becomes part of the conversation
- Prompt injection remains the biggest risk: Anthropic measures a sharp drop in its own tests, but itself calls the chance of an attack "still non-zero"
- Anthropic's own rule of thumb: the built-in Cowork browser for tasks you hand off, Claude in Chrome for the page that is already open. Perplexity Comet has been free since October 2025, ChatGPT Atlas is being discontinued
An AI that clicks, types and fills in forms in your own browser: since 26 August 2026 that has been part of every paid Claude plan. Claude in Chrome has 15 million users in the Chrome Web Store, and according to SE Ranking “claude chrome extension” is searched 18,100 times a month in the United States (as of September 2026). For an SME, what matters most is what you give in return: access to your browser, your logins and whatever is visible in the tabs Claude works in. We put it all in one place, checked against the situation on 12 September 2026, with source and date.
Want AI workflows in your business that work with your tools, with the permissions you decide? ClickForest helps Flemish SMEs in Mechelen, Antwerp and the rest of Flanders with building with AI, from first setup to a working application.
What is Claude in Chrome?
Claude in Chrome is Anthropic’s official browser extension for Google Chrome. With it, Claude views the page you are on and takes actions itself: reading and typing text, clicking links, navigating between pages and filling out forms, using the logins you already have (Anthropic, August 2026). Since 26 August 2026 the extension has been generally available on every paid Claude plan.
It is not new. Anthropic started on 25 August 2025 with a pilot for 1,000 Max users, opened the beta to all Max subscribers on 24 November 2025 and to Pro, Team and Enterprise on 18 December 2025. General availability followed at the end of August 2026. Only the new side panel version still carries the beta label in the help center.
In the Chrome Web Store the extension is simply called “Claude”. It has 15 million users there, with an average rating of 2.8 out of 5 from around 1,600 ratings (as of 12 September 2026). Popular, then, although its users are not unanimously enthusiastic.
Technically, Claude in Chrome is an AI agent: you describe a goal and Claude takes the steps itself. The extension works with all public Claude models and is also available from Claude Cowork and Claude Code.
What can Claude in Chrome do for a business?
Claude in Chrome takes over browser work on the page that is already open, with the accounts you are already signed in to. Anthropic itself names your CRM, your inbox and a document as typical places (Anthropic, August 2026). The extension also has built-in knowledge of Slack, Google Calendar, Gmail, Google Docs and GitHub.
According to the help center, the extension can, among other things:
- work in several tabs at once, gathered in its own tab group;
- schedule tasks that recur daily, weekly, monthly or annually;
- save fixed instructions as shortcuts, called up with a forward slash;
- read console logs, network requests and the structure of a page (the DOM), useful for anyone who builds or tests websites.
For a marketing team it is mostly about recurring clicking work in web tools: copying data from one screen to another, filling in a form, putting figures from a dashboard into a report. An overview of tools per role is in our list of AI tools for marketers.
There are limits too. For files on your computer or other programs you still need the Claude Desktop app, Anthropic writes. And browser work takes more computing power than a regular chat, so the extension uses up your usage limit faster (help center).
How does it work out in practice? After weeks of use, reporter Mahnoor Faisal of XDA Developers called Claude in Chrome “the only AI browser extension actually worth keeping” in April 2026 (XDA, April 2026). That review does predate the Cowork integration and automatic approval.
Which plan and which browser do you need?
You need a paid Claude plan: Pro, Max, Team or Enterprise. The extension only works in Google Chrome on a computer; Anthropic does not support other Chromium-based browsers or mobile devices for now (help center). If you use Microsoft Edge, which also runs on Chromium, you are out of luck. On Enterprise the extension is off by default.
An Enterprise admin turns Claude in Chrome on and can limit it to approved domains (Anthropic, August 2026). On Team and Enterprise, admins can also set an allowlist and a blocklist, and Anthropic recommends starting “with a restrictive allowlist, especially during initial rollout” (admin controls).
You install it from the Chrome Web Store. We did not find a separate country restriction for the extension in Anthropic’s documentation.
Which permissions and data does Claude in Chrome get?
On installation the extension asks for 15 Chrome permissions. The most important is debugger: with it, Claude really operates your browser, clicking, typing and taking screenshots. Claude takes screenshots of the tabs it works in, and everything visible there becomes part of the conversation. Claude cannot filter sensitive content out of that, Anthropic itself writes (help center).
At ClickForest we read a list like that differently, because we built a Chrome extension around Claude ourselves. The Claude Token Tracker shows your Claude.ai usage. Because it asks for no API key, makes no external calls at all and stores everything locally, it passed Google’s in-depth review without any trouble. Claude in Chrome sits at the other extreme: it operates your browser, and what it sees goes into the conversation. An extension like that needs broad permissions, and that is exactly why you choose consciously where you let it work.
These are the permissions, with Anthropic’s own explanation for the most important ones (help center):
| Permission | What it is for | What it means for you |
|---|---|---|
| debugger | Really operating your browser: clicking buttons, typing text and taking screenshots | Claude does in the tabs it works in what you do with mouse and keyboard |
| scripting | Reading text on web pages | What is on the page goes into the conversation |
| tabs and tabGroups | Opening, managing and grouping tabs | Claude works in its own tab group, in several tabs at once |
| alarms | Starting tasks at a set time | Needed for scheduled tasks |
| downloads | Downloading files | Claude asks for permission first, even on sites you always allow |
| nativeMessaging | Connecting with Claude Desktop and Claude Code | The extension talks to the Claude apps on your computer |
| webNavigation | Intervening when you are on a high-risk website | A safety feature |
| declarativeNetRequestWithHostAccess | Identifying itself to Anthropic's servers, so Anthropic sees how the extension is used | Anthropic receives usage data about the extension |
| The other six | Side panel, storage, notifications and display (sidePanel, storage, unlimitedStorage, notifications, system.display and offscreen) | Supporting how the extension works |
Eric Hal Schwartz tested the extension for TechRadar in December 2025 and wrote:
“Every new permission widens the door for Claude to walk through.”
— Eric Hal Schwartz, TechRadar
In the side panel, what Claude sees is also kept. Those sessions go into your history and can be opened on other devices. Anthropic therefore advises against opening the side panel on pages with information you don’t want stored with the session (Use Claude in Chrome safely).
For a business in Belgium or elsewhere in the EU, that touches on the GDPR. If a customer record from your CRM is open in a tab Claude works in, that personal data ends up in the conversation. Anthropic itself advises against using the extension on sites with other people’s personal data.
Does Claude in Chrome ask for permission first?
That depends on the mode you choose: manually approve, automatically approve or skip all approvals. In the Cowork side panel, automatic approval is on by default. Claude then approves the actions it considers safe itself, while a classifier checks every action against your original request and blocks what does not fit. You can switch that feature off in the settings.
Automatic approval arrived on 26 August 2026, using the same mechanism as auto mode in Claude Code (Anthropic, August 2026). The third mode, “Skip all approvals”, used to be called “Act without asking”. If Claude repeatedly runs into blocks, it goes back to asking permission for each step (permissions guide).
Per site you choose between “Allow this action” and “Always allow actions on this site”. Even on a site you always allow, Claude asks for permission first before a download, before entering sensitive data and before granting authorizations. You manage approved sites, revoked permissions and your history in the extension’s settings.
Some actions Claude does not take in any mode, according to the help center: making purchases or financial transactions, creating accounts, bypassing bot verification, placing investment trades and permanently deleting files (permissions guide). Adult content websites and known pirated content sites are blocked, and Claude asks for permission before accessing financial sites (Use Claude in Chrome safely).
Anthropic is not entirely consistent on this. A blog post of 12 August 2026 says Claude asks for permission “before certain irreversible or costly actions, like making a purchase”, and the troubleshooting page still lists financial services and banking among the default blocked categories. So don’t rely on it blindly, and test it yourself on the sites you use.
Is Claude in Chrome safe?
According to Anthropic’s own tests, safer than at the start, although the risk has not gone away. The biggest danger is prompt injection: instructions hidden in a web page that Claude reads as a command. The number of successful attacks has dropped sharply, but Anthropic writes itself that “the chances of an attack are still non-zero”. Those figures have not been independently verified.
The problem runs deep. A language model makes no fundamental distinction between the text on a page and your instruction, so a hidden sentence on a website can come in as an instruction.
During the 2025 pilot, Anthropic ran 123 test attacks across 29 scenarios against the extension. Without protection 23.6% succeeded; with the first safety measures in autonomous mode, 11.2% still did (Anthropic, 2025). Simon Willison, creator of Datasette and co-creator of Django, reacted sharply to that last figure:
“I would argue that 11.2% is still a catastrophic failure rate. In the absence of 100% reliable protection I have trouble imagining a world in which it’s a good idea to unleash this pattern.”
— Simon Willison, creator of Datasette and co-creator of Django, August 2025
A year later the test is stricter and the figures are lower. Anthropic retired the old evaluation because it was “saturated” and now measures with attacks from professional red-teamers. Without extra protection, 17.6% of the attacks that reached the model succeeded against Claude Opus 4.5, and 3.8% against Opus 5. With probes plus a safety classifier, not a single attack succeeded against Sonnet 5, Opus 5 and Mythos 5, and 0.3% did against Fable 5 (Anthropic, August 2026). According to Anthropic, the breakthroughs that remained were checked manually and rated “low-severity”.
These are still Anthropic’s own measurements, on its own test set. The UK cyber security agency NCSC warns that the problem may never go away completely:
“As there is no inherent distinction between ‘data’ and ‘instruction’, it’s very possible that prompt injection attacks may never be totally mitigated in the way that SQL injection attacks can be.”
— David C, Technical Director for Platforms Research at the NCSC
Anthropic says so itself too: “Prompt injection is a moving target”. Research firm Gartner even advised security teams in December 2025 to block AI browsers for now, The Register reported. Critics do see the use, though. Willison, who remains “deeply skeptical” about the whole category of browsing agents, had the extension navigate the Cloudflare dashboard in December 2025, watched “like a hawk” and wrote: “I have to admit this was a very positive experience” (simonwillison.net).
Want to use AI agents without giving them more access than they need? ClickForest builds AI agents for Flemish SMEs in Mechelen, Antwerp and the rest of Flanders, with minimal permissions and a human who approves significant steps.
How does it differ from the built-in browser of Claude Cowork?
Anthropic makes the distinction itself. Cowork’s built-in browser has been in the desktop app since 26 August 2026 and is meant for tasks you hand off while you keep working, such as research or fetching invoices from a supplier portal. Claude in Chrome is for “the page you already have open, with the accounts you’re already signed in to” (Anthropic, August 2026).
What Claude sees differs too. In the built-in browser, Claude does not see your tabs, bookmarks or passwords, you bring logins over per site, and banking, email and single sign-on sites stay out unless you add them yourself. In Chrome, Claude works in your own browser, with the sessions already open there. More about the Cowork browser is in our explanation of Claude Cowork.
You choose which browser Cowork uses under Settings → Cowork → Preferred browser. If you already use Claude in Chrome, it stays your default; otherwise Claude takes the built-in browser. Without the desktop app, on the web, the extension remains the only way to give Claude a browser.
Since 12 August 2026 a Cowork session can also run in the extension’s side panel (Anthropic, August 2026). That side panel works like Cowork on the desktop: conversations go into your history, skills, plugins and connectors based on MCP simply work there, and you continue a session on the web, desktop or mobile. Max and Team got it straight away, and Pro was to follow in phases over the following weeks. If you record workflows, you can only do that in the classic side panel.
Anna Washenko of Engadget called it “a helpful upgrade for anyone performing a lot of tasks in the Google-owned browser” at launch (Engadget, August 2026).
How does Claude in Chrome compare to Perplexity Comet and ChatGPT Atlas?
Claude in Chrome is an extension in the browser you already use. Perplexity Comet is a full browser, free for everyone since 2 October 2025. ChatGPT Atlas, OpenAI’s standalone browser, is being discontinued: OpenAI announced on 9 July 2026 that Atlas is stopping, and the browser was scheduled to stop working from 9 August 2026.
| Tool | What it is | Where it works | Status September 2026 |
|---|---|---|---|
| Claude in Chrome | Extension by Anthropic | Google Chrome on a computer | Generally available on every paid Claude plan since 26 August 2026 |
| Built-in Cowork browser | Browser in the Claude Desktop app | macOS and Windows, Linux in beta | Rolling out to Pro, Max and Team since 26 August 2026, on Enterprise via the admin |
| Perplexity Comet | Full AI browser by Perplexity | Mac, Windows, iOS and Android | Free since 2 October 2025 |
| ChatGPT Atlas | Standalone browser by OpenAI | Arrived on the Mac in October 2025 | Discontinuation announced on 9 July 2026, scheduled from 9 August 2026 |
Comet appeared in July 2025, at first for Perplexity Max subscribers and through a waitlist (TechCrunch, July 2025), and has been free worldwide since 2 October 2025 (Perplexity, October 2025). It is a separate browser that you install next to Chrome. What Perplexity itself is good at is covered in our practical guide to ChatGPT, Claude and Perplexity.
Comet also had to deal with prompt injection. Security researchers at Brave reported a vulnerability via indirect prompt injection in July 2025, made it public on 20 August 2025 and wrote in a later update that Perplexity had not yet fully mitigated that type of attack (Brave, as of August 2025). Their description of the risk fits any browsing agent that works with your logins:
“The AI operates with the user’s full privileges across authenticated sessions, providing potential access to banking accounts, corporate systems, private emails, cloud storage, and other services.”
— Artem Chaikin and Shivan Kaul Sahib, Brave
OpenAI went a different way. Atlas arrived on the Mac in October 2025, but on 9 July 2026 James Sun of OpenAI wrote on X: “we are going to be sunsetting Atlas” (9to5Mac, July 2026). According to OpenAI’s help center, the browser features are moving to the new ChatGPT desktop app and to a ChatGPT extension or sidebar for Chrome, where available. Bookmarks are not carried over automatically. Notably, OpenAI is choosing the same form as Anthropic: a desktop app plus an extension in Chrome.
How do you use Claude in Chrome safely as an SME?
Start small, with as little access as possible. Anthropic recommends a separate browser profile without banking, healthcare or government accounts, and advises against using the extension for financial accounts, legal documents, medical information or work accounts with sensitive business data. Then set approval to manual and let Claude work on sites you trust first.
Rami McCarthy, principal security researcher at Wiz, gave TechCrunch a useful rule of thumb: “autonomy multiplied by access” (TechCrunch, December 2025). The more Claude may decide on its own and the more accounts are open, the greater the risk. For an SME, that becomes concrete:
- a separate Chrome profile for Claude, without your bank, your accounting or a mailbox full of customer data;
- manual approval until you know how Claude behaves on your sites, and only then automatic;
- on a Team or Enterprise plan, a limited allowlist of domains, as Anthropic itself recommends;
- no side panel on pages with customer records or other personal data;
- a precise instruction, because in automatic mode a classifier checks every action against what you asked (tips in write better prompts).
Anthropic is clear about who remains responsible: “You remain responsible for all browser actions taken by Claude”.
ClickForest applies the same rule to marketing automation for Flemish SMEs in Mechelen and Antwerp: minimal access, maximum control. For recurring work between fixed systems, a connection via an API or MCP is more predictable, because it does not depend on what a web page looks like today. A browsing agent then comes into play for portals that have no connection. When each approach fits is covered in AI agents in marketing and marketing automation for SMEs.
There is also a side that concerns your own website. If visitors let an agent do the clicking, your site also has to be usable for that agent, with clear buttons and forms. How webshops prepare for that is in our piece on agentic commerce; visibility in AI answers itself is the domain of GEO.
Conclusion: a colleague in your browser, with your keys
Claude in Chrome puts AI in the middle of your daily work: Claude works in your own browser, with your own logins, on the page that is already open. That makes the extension useful for clicking work in a CRM, an inbox or a portal without a connection. It also explains why the list of permissions matters.
Our advice: install the extension in a separate Chrome profile, start with manual approval and one recurring task, and watch along for the first few weeks. If it works, you allow more step by step. If you want to hand off a task completely, the built-in browser of Claude Cowork is often the more logical choice. Which AI tool suits which task is covered in the best AI tool per task and in our overview of the superpowers of each AI tool.
ClickForest helps Flemish SMEs and scale-ups in Mechelen, Antwerp and beyond make those choices and set up the workflows safely, with AI training, AI agents and the rest of AI for growth.
Grow with AI, practically and without unnecessary complexity
Ready to use AI to save time and accelerate your marketing? Discover our AI services
Discuss your challenge directly with Frederiek: Book a free strategy call or send us a message
Prefer email? Send your question to frederiek@clickforest.com or call +32 473 84 66 27
Strategy without action remains theory. Let's take your next step together.
Frequently asked questions
Claude in Chrome is Anthropic's official browser extension for Google Chrome. With it, Claude views the page you are on and takes actions itself: reading and typing text, clicking links, navigating between pages and filling out forms, using the logins you already have. Since 26 August 2026 the extension has been generally available on every paid Claude plan.
According to Anthropic's own tests, safer than at the start, although the risk has not gone away. The biggest danger is prompt injection: hidden instructions on a web page that Claude reads as a command. The number of successful attacks has dropped sharply, but Anthropic says the chance is still above zero. That is why ClickForest builds AI agents for Flemish SMEs in Mechelen and Antwerp with minimal permissions and a human who approves significant steps.
A paid Claude plan: Pro, Max, Team or Enterprise, so not the free plan. On Enterprise the extension is off by default until an admin turns it on, optionally limited to approved domains. For now, Claude in Chrome only works in Google Chrome on a computer, not in other Chromium-based browsers such as Microsoft Edge and not on mobile devices.
Cowork's built-in browser lives in the Claude Desktop app and is meant for tasks you hand off while you keep working; Claude does not see your tabs, bookmarks or passwords there. Claude in Chrome works on the page you already have open, with the accounts you are already signed in to. If you already use the extension, it stays the default for Cowork.
Use a separate Chrome profile without banking, healthcare or government accounts, set approval to manual and let Claude work on sites you trust first. Keep pages with customer data out of view, because whatever is visible becomes part of the conversation. ClickForest guides Flemish SMEs and scale-ups in Mechelen, Antwerp and the rest of Flanders in this with AI training and AI agents.
Sources and references
Official Anthropic sources:
- Anthropic (Claude blog): "Claude in Chrome is generally available" (26 August 2026) · https://claude.com/blog/claude-in-chrome-generally-available
- Anthropic (Claude blog): "Piloting Claude in Chrome" (2025) · https://claude.com/blog/claude-for-chrome
- Anthropic (Claude blog): "Claude Cowork comes to the Chrome side panel" (12 August 2026) · https://claude.com/blog/cowork-chrome-side-panel
- Anthropic (Claude blog): announcement of the built-in browser in Cowork (26 August 2026) · https://claude.com/blog/cowork-built-in-browser
- Claude Help Center: "Get started with Claude in Chrome" (2026) · https://support.claude.com/en/articles/12012173-get-started-with-claude-in-chrome
- Claude Help Center: "Use Claude in Chrome safely" (2026) · https://support.claude.com/en/articles/12902428-use-claude-in-chrome-safely
- Claude Help Center: "Claude in Chrome permissions guide" (2026) · https://support.claude.com/en/articles/12902446-claude-in-chrome-permissions-guide
- Claude Help Center: "Claude in Chrome admin controls" (2026) · https://support.claude.com/en/articles/13065128-claude-in-chrome-admin-controls
- Claude Help Center: "Claude in Chrome troubleshooting" (2026) · https://support.claude.com/en/articles/12902405-claude-in-chrome-troubleshooting
- Chrome Web Store: the "Claude" extension (consulted September 2026) · https://chromewebstore.google.com/detail/claude/fcoeoabgfenejglbffodgkkbkcdhcgfn
Perplexity and OpenAI:
- Perplexity: "The Internet is Better on Comet" (2 October 2025) · https://www.perplexity.ai/hub/blog/comet-is-now-available-to-everyone-worldwide
- CNBC: "Perplexity AI rolls out Comet browser for free worldwide" (October 2025) · https://www.cnbc.com/2025/10/02/perplexity-ai-comet-browser-free-.html
- OpenAI Help Center: "Evolving Atlas into ChatGPT for browser-based agentic work" (2026) · https://help.openai.com/en/articles/20001371-evolving-atlas-into-chatgpt-for-browser-based-agentic-work
- 9to5Mac: "OpenAI is discontinuing ChatGPT Atlas, its standalone desktop browser" (July 2026) · https://9to5mac.com/2026/07/09/openai-is-discontinuing-chatgpt-atlas-its-standalone-desktop-browser/
Media, experts and security agencies:
- Simon Willison: on the Claude in Chrome pilot (August 2025) · https://simonwillison.net/2025/Aug/26/piloting-claude-for-chrome/
- Simon Willison: a test of Claude in Chrome (December 2025) · https://simonwillison.net/2025/Dec/22/claude-chrome-cloudflare/
- TechRadar: "I tried the new Claude in Chrome extension" (December 2025) · https://www.techradar.com/ai-platforms-assistants/claude/i-tried-the-new-claude-in-chrome-extension-and-it-delivered-convenience-with-a-side-of-digital-paranoia
- XDA Developers: review of Claude in Chrome (April 2026) · https://www.xda-developers.com/claude-in-chrome-first-browser-ai-extension-i-didnt-immediately-hate/
- Engadget: "Claude Cowork can now run in a Chrome sidebar" (August 2026) · https://www.engadget.com/2235919/claude-cowork-can-now-run-in-a-chrome-sidebar/
- TechCrunch: "OpenAI says AI browsers may always be vulnerable to prompt injection attacks" (December 2025) · https://techcrunch.com/2025/12/22/openai-says-ai-browsers-may-always-be-vulnerable-to-prompt-injection-attacks/
- NCSC: "Prompt injection is not SQL injection (it may be worse)" (December 2025) · https://www.ncsc.gov.uk/blog-post/prompt-injection-is-not-sql-injection
- Brave: "Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet" (2025) · https://brave.com/blog/comet-prompt-injection/
- The Register: "Block all AI browsers for the foreseeable future: Gartner" (December 2025) · https://www.theregister.com/software/2025/12/08/block-all-ai-browsers-for-the-foreseeable-future-gartner/2793276






