Anthropic has upgraded Claude in Chrome so browser work is no longer isolated from the rest of a user’s Claude account, according to Digital Trends. The report says the Chrome side panel now runs as a full Claude Cowork session, allowing conversations, skills, and connectors to move between the browser extension and Claude’s desktop, web, and mobile apps. That changes a basic workflow constraint. Digital Trends reports that, before the update, Claude browser sessions were separate from other Claude surfaces, so a user who started work in the browser had to restart or recreate context when moving to another device or app. With the new setup, a task begun in Chrome can reportedly be resumed later in Claude’s desktop app, web app, or mobile app. The browser agent can also interact with webpages more directly. Digital Trends says Claude in Chrome can see the page a user is viewing and take actions inside it, including clicking links, entering text, filling out forms, and moving between pages while using the user’s existing logins. The report frames this as useful for systems that do not connect directly to Claude, such as internal dashboards, legacy software, and vendor portals. One example in the report is a budget workflow built from invoices spread across several vendor sites. In that scenario, Claude could open tabs, extract amounts and dates, and begin building a spreadsheet. Because the session is tied to the account rather than only the browser instance, Digital Trends says the same work could later continue in the desktop app, where a user might add local files or compare the output with prior-month numbers. The update fits a broader push to let Claude operate across web-based work contexts. Digital Trends notes that Anthropic has also been expanding web interaction inside Claude Code, including a separate in-app browser that lets the coding assistant read documentation without leaving the development environment. The same capabilities introduce a sharper security surface. Digital Trends highlights prompt injection as the main risk: hidden instructions inside a webpage or document can try to steer an AI agent away from the user’s intent. The report notes that recent security research has found serious issues across multiple AI browsing tools, making this a practical concern rather than a theoretical one. Anthropic’s mitigation, according to Digital Trends, is a new review step for consequential actions. The check compares actions such as submitting a form or sending a message against the user’s original request before they happen. The report also says Claude will still ask for permission before actions such as making a purchase or sharing personal information. Availability is limited at launch. Digital Trends reports that the update is live now for Max and Team plans, that Pro access will roll out in the coming weeks, and that Enterprise administrators can enable it selectively by domain. Who benefits: Claude users who work across vendor portals, internal dashboards, legacy systems, or other tools without direct connectors stand to benefit most. Max and Team users get access first, according to Digital Trends. Who's exposed: Users and organizations that allow browser agents to act inside logged-in sessions take on prompt-injection risk. Enterprise admins will need to decide where selective domain enablement is appropriate.