AIToday
Large Language ModelsAI Business & IndustryITmedia AI+Published: Sep 24, 2026, 10:01 JST

Anthropic's Claude in Chrome goes GA, attack success under 0.3%

Anthropic's Claude in Chrome goes GA, attack success under 0.3%

3 Key Points

  1. What happened

    Anthropic said Claude in Chrome, first launched as a pilot in 2025, is now generally available on all paid Claude plans, and in its July evaluation no successful prompt-injection attacks reached Claude Sonnet 5, Claude Opus 5 or Claude Mythos 5, with only 0.3% against Claude Fable 5.

  2. Why it matters

    Autonomous browser agents were seen as highly susceptible to prompt injection, so Anthropic's reads suggest that combining a probe that scans tool output with a safety classifier may leave attackers very little room in current models.

  3. What to watch

    The result holds only inside Anthropic's own evaluations, and the company says attacks that do land can go unnoticed, so the test is whether this holds as attacks change; watch the 0.3% figure for Claude Fable 5.

WHO IT HITSAnthropic's claims land on IT administrators and security teams at companies that turn on Claude in Chrome via the Chrome Web Store, who can limit it to approved domains or disable it under Enterprise plans.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

Anthropic is extending Claude in Chrome from a 2025 pilot to general availability on every paid Claude plan, meaning the assistant is now allowed to read the open page and perform actions such as reading and entering text, clicking links, moving between pages and filling in forms. It supports multiple tabs, and Anthropic says it works not only on the desktop app but also on the mobile app and the web app. Not every site is reachable: connections to internal dashboards and legacy systems, or to sites that block the connection, are not supported, and it does not work outside Chrome on Chromium-based browsers or in mobile environments.

Prompt injection is the reason this is a riskier product than a normal chat assistant. A page, email or form can carry a hidden instruction that the user never sees, and an agent can be steered into acting on it, for example forwarding a sensitive email if Claude is helping with replies. Anthropic says it uses an attack library built from internal tests, external red teams and its own monitoring to harden the model, and that the probe and safety classifier have cut attacks sharply: in its October evaluation over 129 scenarios and 10 runs each, reaching Claude Opus 4.5 succeeded 17.6% and Claude Opus 5 3.8%; with probe and classifier, models from Claude Opus 4.8 on saw almost no successful attacks. Anthropic also notes not every attack reaches the model, and that attack methods keep changing, so it plans to release attacks with new models and to keep improving red-teaming and the classifiers. The stakes for business users, then, are likely to hinge on how well that cat-and-mouse cycle keeps up.

FAQ
Does Claude in Chrome still ask me to approve each action?
No. Anthropic said Claude now operates the browser autonomously without asking for user approval for each action, and instead a safety classifier checks actions in advance. It compares the action with your original request and blocks it if it does not match.
What defenses does Anthropic use against prompt injection?
It uses three: hardening the model through attack red-teaming, a probe that scans the page or email content returned as tool results and blocks suspicious ones, and advance screening by a safety classifier. The probe first shipped in Claude Opus 4.5.
Can administrators control Claude in Chrome at work?
Yes. Under Enterprise plans, administrators can manage usage in organization settings and restrict it to approved domains, and Anthropic said the classifier can be turned off in settings where needed.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Pangram AI detector flags Orelien novel claimJapan Times Tech · 1h ago
  • OpenAI models tapped SEC.gov, Census.gov dataJapan Times Tech · 1h ago
  • Microsoft Copilot rebuilt with Home, Code, Autopilot tabsITmedia AI+ · 4h ago

AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleTwilio lifts 2026 outlook to 18% to 18.5% on 22% Q2 growth