Anthropic's Claude in Chrome Now Runs Full Cowork Sessions Across Every Device

Claude in Chrome's side panel now runs a full Cowork session, syncing conversations, skills, and connectors across desktop, web, and mobile

·
·
Read5 min
TopicAgents · Api
  • Session sync: Claude in Chrome's side panel now runs a full Cowork session, syncing conversations across desktop, web, and mobile.
  • Availability: Live now for Max and Team plans; Pro rollout coming in the next few weeks.
  • Skills and connectors carry over: Any skill or connector configured in Cowork is automatically available in the browser side panel with no extra setup.
  • Browser agent use cases: Pulling dashboard metrics, organizing Drive files, logging CRM calls, and competitor research without copy-pasting.
  • Prompt injection defenses: Dual classifiers plus RL-trained robustness reduce attack success rates to under 0.08% in internal testing, though risk is non-zero.
  • Hard limits: Not for financial accounts, health records, legal docs, or HIPAA-covered orgs -- a separate browser profile is recommended for Claude work.

Claude in Chrome just got a meaningful upgrade. The browser extension's side panel now runs a full Claude Cowork session, the same one tied to your account across desktop, web, and mobile. Conversations you start in a Chrome tab carry over to the desktop app or your phone without any manual handoff.

One session, every surface

Previously, the Chrome extension lived in its own isolated context. Now, the side panel runs a full Cowork session, and the skills, plugins, and connectors you've already built are available with nothing to set up in the browser.

Every conversation saves to your history. Sessions live with your account rather than the machine, so you can begin in Chrome and pick up on desktop or mobile without re-explaining anything. Cowork runs in the cloud and syncs to your Claude account, letting you kick off a task at your desk and check status from your phone on the train home.

What Cowork actually is

For anyone who hasn't used it yet, Claude Cowork (short for "collaborative work") is Anthropic's persistent agent workspace. Chats, projects, and artifacts sit together in one place, and an agent can act across them rather than in a single throwaway conversation. Think of it as a long-running session where Claude has memory, tools, and context, instead of a fresh chat each time you open a tab.

The Chrome extension specifically lets Claude interact with whatever page you're on. It reads the page you're signed in to, then clicks, types, and fills forms while you decide what happens next. Pairing that with a persistent Cowork session turns the browser into one step in a longer workflow rather than an isolated interaction.

What you can actually do with it

The practical use cases are genuinely useful for repetitive browser-based work:

  • Analytics dashboards: Claude navigates your analytics tool, pulls the numbers, and compiles a summary without manual copying or exporting.
  • Google Drive organization: Sort files, create folder structures, and flag duplicates for your review.
  • CRM logging: Read your calendar, match attendees to Salesforce contacts, and draft activity logs for each call.
  • Competitor research: Pair Claude in Chrome with Cowork so the browser navigates and gathers while Cowork produces Excel models, comparison decks, and reports.
  • Email cleanup: Scan your inbox for marketing messages and newsletters, then present them as a list for bulk deletion.

One capability worth calling out: Claude can reach internal tools, legacy portals, admin consoles, and invoice systems using the logins you already have on the tab in front of you. Most enterprise software has no public API. The browser is the only interface, and Claude can use it.

The prompt injection problem

Browser agents face a security threat that doesn't exist in normal chat: prompt injection. A malicious website embeds hidden instructions in its content, invisible to you but processed by the model, that try to redirect Claude's behavior. Picture a webpage containing invisible text telling Claude to forward your emails to an external address while appearing to help you draft replies.

Claude in Chrome runs safety classifiers that screen for these attacks automatically. One checks incoming content for injection attempts, and another checks every action Claude takes before it runs. On the model side, Anthropic uses reinforcement learning to build injection robustness into Claude's capabilities directly, exposing it to injections embedded in simulated web content during training.

The numbers are encouraging but honest. The current configuration reduces attack success rates to less than 0.08% against internal testing that combines known effective attack techniques. Anthropic is transparent that this isn't zero. Novel attacks may emerge that evaluations didn't cover, and a successful one could lead to outcomes like data exfiltration. The full technical breakdown lives in the prompt injection research post.

Where not to point it

Anthropic is explicit about where this tool doesn't belong. The official safety guide strongly advises against using Claude in Chrome for:

  • Managing financial accounts or investments
  • Handling legal documents or contracts
  • Processing medical or health information
  • Accessing work accounts with sensitive company data

Claude in Chrome isn't available to organizations covered by HIPAA, and Anthropic recommends against using it on pages that contain regulated data. A practical privacy note: to see a page and decide what to do next, Claude takes screenshots of the tabs it's working in, and whatever is visible becomes part of the conversation. A separate browser profile for Claude work is a reasonable precaution.

Availability and plans

The Cowork session integration in the Chrome side panel is available now on Max and Team plans, with Pro rolling out over the coming weeks. Claude in Chrome itself is generally available on all paid plans (Pro, Max, Team, and Enterprise), though the Cowork sync is the new piece landing today. The extension installs from the Chrome Web Store.

For Team and Enterprise admins, org-wide controls can enable or disable the extension, and allowlists and blocklists restrict which sites Claude can access. Those are the right levers to pull before rolling this out to a team handling sensitive data.

Comments

avatar