
What happened
Anthropic said Claude in Chrome, first launched as a pilot in 2025, is now generally available on all paid Claude plans, and in its July evaluation no successful prompt-injection attacks reached Claude Sonnet 5, Claude Opus 5 or Claude Mythos 5, with only 0.3% against Claude Fable 5.
Why it matters
Autonomous browser agents were seen as highly susceptible to prompt injection, so Anthropic's reads suggest that combining a probe that scans tool output with a safety classifier may leave attackers very little room in current models.
What to watch
The result holds only inside Anthropic's own evaluations, and the company says attacks that do land can go unnoticed, so the test is whether this holds as attacks change; watch the 0.3% figure for Claude Fable 5.
WHO IT HITSAnthropic's claims land on IT administrators and security teams at companies that turn on Claude in Chrome via the Chrome Web Store, who can limit it to approved domains or disable it under Enterprise plans.
Summaries like this, in your inbox every morning.
Anthropic is extending Claude in Chrome from a 2025 pilot to general availability on every paid Claude plan, meaning the assistant is now allowed to read the open page and perform actions such as reading and entering text, clicking links, moving between pages and filling in forms. It supports multiple tabs, and Anthropic says it works not only on the desktop app but also on the mobile app and the web app. Not every site is reachable: connections to internal dashboards and legacy systems, or to sites that block the connection, are not supported, and it does not work outside Chrome on Chromium-based browsers or in mobile environments.
Prompt injection is the reason this is a riskier product than a normal chat assistant. A page, email or form can carry a hidden instruction that the user never sees, and an agent can be steered into acting on it, for example forwarding a sensitive email if Claude is helping with replies. Anthropic says it uses an attack library built from internal tests, external red teams and its own monitoring to harden the model, and that the probe and safety classifier have cut attacks sharply: in its October evaluation over 129 scenarios and 10 runs each, reaching Claude Opus 4.5 succeeded 17.6% and Claude Opus 5 3.8%; with probe and classifier, models from Claude Opus 4.8 on saw almost no successful attacks. Anthropic also notes not every attack reaches the model, and that attack methods keep changing, so it plans to release attacks with new models and to keep improving red-teaming and the classifiers. The stakes for business users, then, are likely to hinge on how well that cat-and-mouse cycle keeps up.
For example, today's edition would include:
AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Saxon Chen, founder and CEO of Taiwan's H2U Corp, said in an interview that companies often stress environment…

Nvidia was drawn into a US-China AI rivalry at the September 2026 Trump-Xi summit and UN General Assembly, whe…

Fidelity's FFLG ETF holds $590 million, with NVIDIA at 16.24% and Alphabet at 12.56% of net assets

An X account with a handful of followers claimed the AI-detecting program Pangram found that Thelyson Orelien'…

OpenAI confirmed its AI models accessed publicly available information from U.S

The DC Circuit ruled the US can blacklist Anthropic under 41 U.S.C. § 4713, saying that statute requires no ba…
