Claude Cowork now has its own built-in sandboxed browser
Claude Cowork on the desktop app now includes a sandboxed browser that opens in a side panel, so the agent can navigate sites without touching your own browser.
Anthropic has added a built-in sandboxed browser to Claude Cowork on the desktop app. When Claude needs to visit a website as part of a task, a Chromium-based browser now opens in a side panel next to your conversation. Claude navigates pages, clicks, types, and fills forms while you watch. No Chrome extension required, and nothing from your own browser is involved unless you choose to share it.
What changed and why it matters
Until now, giving Claude web access in Cowork meant installing the Claude in Chrome extension and letting it operate inside your personal browser. That approach makes sense when Claude needs to work on a page you already have open. But a large number of web tasks don’t need your browser specifically, they just need a browser. Internal dashboards, vendor portals, legacy systems, and anything else that lacks a direct connector all fall into that category. The built-in browser is how Claude handles those without requiring you to hand over access to your tabs, bookmarks, or saved passwords.
The browser launches with a clean profile each time. No inherited cookies, no browsing history, no logins carried over from your everyday browsing. The first time it opens, you’ll see an option to import cookies from your personal browser if you want Claude to stay signed in to specific sites. That step is opt-in.
How it works in practice
When a Cowork task involves a website, the browser opens automatically in the side panel. You don’t need to do anything to trigger it. Claude opens the relevant site, reads the page, and takes whatever actions the task requires: pulling figures from a dashboard, filling out a multi-step form, navigating a portal to find a document. You can watch it work in the panel without switching windows.
Links in the task transcript open in the same side panel, so everything stays in one place.
If you already use Claude in Chrome and prefer to keep it that way, nothing changes. You can set your preference under Settings, then Cowork, then Preferred browser. The options are “Built-in browser” or “Chrome (Claude in Chrome)”, and you can switch at any time. Claude uses whichever you’ve set as default unless you ask it to use the other one for a specific task.
What this means for you
On Pro and Max plans: The built-in browser is rolling out to the Claude desktop app across macOS, Windows, and Linux (Linux is in beta) from late August 2026. Once it reaches you, it’s on by default. Nothing to install, and it doesn’t interfere with your personal browser in any way. The most practical use is offloading web-based steps you’d otherwise do yourself: logging into a portal to pull a number, submitting a routine form, or checking a supplier’s site that has no API or connector.
On Team plans: The rollout follows the same timeline as Pro and Max. The built-in browser is available to the whole team once it reaches your organisation.
On Enterprise plans: Admins have access from the date of announcement and can manage rollout at the organisational level via Organisation settings, then Cowork, then Built-in browser. That means you can enable it selectively before it reaches the broader team.
On web or mobile: The built-in browser lives in the desktop app, so Claude Desktop needs to be open and online for Claude to use it. If you start a Cowork session on desktop, you can steer it from a browser tab or your phone while the desktop app stays running. On web without the desktop app open, Claude in Chrome remains the way to give Claude a browser.
A note on security
The built-in browser carries the same prompt injection risks as any AI agent that operates in a browser. A page could contain instructions designed to redirect Claude away from your original task. Anthropic applies the same safeguards here as it does in Claude in Chrome, including checks that compare Claude’s actions against what you actually asked for. Those measures reduce the risk meaningfully but don’t eliminate it. Anthropic’s own guidance is to start with sites you trust while the feature is new.
The sandboxing itself is worth understanding clearly: Claude’s browser is isolated from your personal browser. It cannot see your tabs, read your bookmarks, or access any credentials stored in your everyday browser profile. The separation is structural, not just a setting.
The bigger picture
The Claude Code tab has had a built-in browser since July 2026, used mainly by developers previewing web apps and browsing documentation in a sandboxed pane. This announcement extends that capability to Cowork for non-developer tasks, which is where most users spend their time.
The Claude desktop app now combines chat, agentic task work, local file access, terminal execution, and embedded browsing in a single application. That’s a practical shift for anyone who has been stitching together browser extensions, API connectors, and manual copy-paste steps to get Claude to interact with the web.
If your work regularly involves web portals or tools that have no direct integration, this is the update to pay attention to.