Anthropic's browser extension Claude in Chrome moved to general availability on August 26, 2026. What used to be a limited pilot is now installable from the Chrome Web Store by anyone on a paid plan. The release also drops the requirement to approve every single action: anything a safety classifier clears is carried out automatically.
Per-action approval is gone
The most noticeable change is what happens to the approval dialog. Previously, opening a link or typing text prompted a request for permission each time. In the general release, Claude auto-approves actions it judges to be safe. The mechanism is the same one behind auto mode in Claude Code: just before an action runs, a classifier inspects it and blocks anything that does not line up with the original request.
For anyone uncomfortable with that, the manual approval flow is still available as a setting. Being able to decide how much latitude to hand over is a practical consideration for workplace use.
Reaching tools that never connected, through screens you are already logged into
Anthropic is investing in a browser extension because so many work tools still have no connector. Internal dashboards, long-running legacy systems, vendor portals set up by business partners: screens without a public API are common.
Claude in Chrome treats those screens as they appear. It reads the page you have open and performs actions such as reading and typing text, clicking links, navigating between pages, and filling out forms, all within the session you are already signed into. Because no new credentials have to be handed over, there is less to trip over before getting started.
Three layers of prompt injection defense
An agent acting autonomously in a browser inevitably faces prompt injection, where malicious instructions are planted in web pages, emails, or form fields. Ask Claude to draft replies to your email, and a hidden instruction in one message could tell it to forward your other mail to an attacker instead. Anthropic says it spent the stretch between the pilot and general availability hardening this area.
The defenses fall into three groups. The first is model robustness. A growing library of attacks, sourced from internal automated attackers, external red-teamers, and real-world monitoring, feeds into training. Whenever a new attack succeeds, it goes into the library.
The second is a set of probes. Web content reaches the model as tool results, so those results are scanned for signs of injected instructions. When a probe flags something, Claude treats the content as suspect and checks with the user before acting if necessary. Probes were first deployed with Claude Opus 4.5, and the range of attacks they cover has widened since.
The third is the pre-execution check described above, which compares individual actions such as navigation or text entry against the original request. Stacking gates of different kinds, on the model, on the input, and on the output, is the defining feature of this setup.
How to read the attack success rates
Anthropic has published evaluation results. The initial evaluation set built during the pilot ended up at a 0 percent attack success rate against Fable 5, Opus 5, and Sonnet 5, so it was retired as saturated.
The current evaluation uses stronger attacks sourced from professional red-teamers. With additional safeguards turned off, 17.6 percent of the attacks that reached Opus 4.5 succeeded, along with 3.8 percent against Opus 5. Even with probes, the strongest safeguard available in November 2025, 16.7 percent still got through on Opus 4.5.
With both probes and the safety classifier running on models from Opus 4.8 onward, no attacks succeeded against Sonnet 5, Opus 5, or Mythos 5. Only Fable 5 retained a 0.3 percent success rate, and Anthropic says it manually verified that all of those occurred in low-severity scenarios and is working to mitigate them.
These figures apply to one specific evaluation set. Prompt injection is an area where attackers keep changing tactics, so there is no guarantee the 0 percent figure holds. Anthropic itself writes that it must continue investing in automated attack discovery, red-teaming, and stronger classifiers.
Getting started, and what is still out of reach
Setup is simply a matter of adding the extension from the Chrome Web Store. On Enterprise plans, admins can manage availability in Organization Settings and restrict it to approved domains.
Limits remain. Working with files on your own machine, or with applications outside the browser, still requires the desktop app. Other Chromium-based browsers and mobile environments are not supported. Since work started in the browser can be continued in the desktop, mobile, and web apps, the accurate framing is that another entry point has been added.
Summary
General availability for Claude in Chrome reads less like a feature addition and more like a decision to cut approval overhead, backed by safety testing. With probes layered on top of a pre-execution classifier, attack success rates for the major models drop to 0 percent on the current evaluation. The benefit is easiest to see in environments where people work daily with internal systems that never shipped an API.
