Letting an agent use your browser without handing it your accounts
What to lock down before an AI agent starts clicking inside your logged-in browser, and how to widen its reach without losing track of what it can touch.
on this page · 0 / 0 checked
Count the tabs you have open right now. The invoicing tool with your bank details on file. The hosting panel with the delete button. The client’s CMS where you can publish. Email, which is where every password reset in your life lands. You are logged into all of it, all day, because that is what a working browser is.
An AI agent is now being offered to you inside that same window, and increasingly it is offered switched on rather than as something you go and enable. This guide is about what to set up before it starts clicking, written for the person who is the whole IT department, which is to say the person who is also the one billing clients this afternoon. If you have a security team, a managed Chrome fleet and a policy on browser extensions, you need your own rollout document and this is not it.
The agent borrows your logged-in authority
A chat model that reads a web page can be wrong in a paragraph. An agent that drives your browser can be wrong in your name. It clicks with your cookies, your session tokens, your saved addresses and your open sessions, and the sites it touches cannot tell the difference between it and you, because from their side there is no difference. The blast radius is not the model’s knowledge. It is your account list.
The clearest published example is worth walking through slowly. Brave’s security researchers tested Perplexity’s Comet browser by asking it to summarise a Reddit page that carried instructions hidden behind a spoiler tag, invisible to a reader glancing at the thread [8]. The agent read them and followed them. It navigated to the user’s account page, extracted the email address, went to Gmail to retrieve a one-time password, and then posted that code back as a reply to the original comment, where the attacker was waiting [8]. Brave reported it on 25 July 2025, found three days later that Perplexity’s first fix was incomplete, and disclosed publicly on 20 August 2025 [8].
No exploit code was involved. No password was cracked. The attack was a paragraph of English on a page, aimed at a helpful assistant with a logged-in browser. That is why Brave’s conclusion is about architecture rather than about one bug: “Traditional Web security assumptions don’t hold for agentic AI, and that we need new security and privacy architectures for agentic browsing” [8]. The same-origin policy stops a hostile page’s script from reading your mail tab. It does nothing about an assistant that reads the hostile page, believes it, and then walks over to the mail tab itself.
The capability arrives switched on
The uncomfortable part of the current moment is that this is no longer a thing you opt into by installing something obscure. Anthropic ran Claude in Chrome as a pilot with 1,000 Max users in August 2025, opened it to all Max subscribers on 24 November 2025, and extended it to Pro, Team and Enterprise plans on 18 December 2025 [1]. On Team plans the extension is enabled by default, and Anthropic’s admin documentation states that for Enterprise, where it has been disabled by default, “Starting September 10, 2026, it turns on by default unless you’ve already disabled it” [4]. Google is doing the same thing in the browser most people already use. Gemini in Chrome now includes an auto-browse capability described as “From appointment booking to party planning, tell Gemini what you need and watch it handle the rest on your behalf”, rolling out “first in preview to Google AI Pro and Ultra subscribers in the U.S.” [7].
The second thing worth internalising is that the surface moves under you. OpenAI shipped a whole browser for this, then reversed course: “We’re deprecating Atlas and moving browser-based agentic capabilities into ChatGPT and Codex”, with Atlas “scheduled to stop working on August 9, 2026” and the capability reappearing in the desktop app and a Chrome extension, including “multiple tabs, downloads, improved navigation, account login support” [5]. Read that last phrase twice. The direction of travel is toward agents that are logged in, not agents that browse as strangers.
So the settings you tighten today are attached to a product that may be renamed, folded into something else, or defaulted differently in six months. Put a recurring 20 minutes in the calendar to re-open the permissions screen of whatever you use. Configuration is not a one-time task when the vendor keeps shipping.
A second browser profile is the cheapest control you own
The single highest-value move takes about four minutes, and it is the one the vendor recommends first. Anthropic’s safety guidance for Claude in Chrome says to “Use a separate browser profile without access to sensitive accounts (such as banking, healthcare, government)”, and adds that Anthropic “strongly advise against using Claude in Chrome to manage or take actions on sensitive information”, financial accounts and work accounts holding sensitive data among the examples it gives [3].
Make a new Chrome profile. Call it something you will recognise in a screenshot. Install the agent extension there and only there. Then log in to the two or three services the work actually needs, and stop. The test for whether an account belongs in that profile is not whether the agent might find it handy. It is what happens if a web page the agent reads today turns out to be hostile.
One account deserves a rule of its own. Keep the mailbox that receives your password resets out of the agent profile entirely. That mailbox is what turned the Comet demonstration from an embarrassing summary into an account takeover, because a one-time code sitting in an inbox is a skeleton key for everything else [8]. If the agent cannot open your mail, a great many attack chains end early with nothing to steal.
Site permissions are the actual configuration
Everything after the profile is scope. Claude in Chrome offers three approval modes, listed in the permissions guide as “Manually approve (Manual)”, “Automatically approve (Auto)” and “Skip all approvals (Skip)”, where the last is documented for cases in which you completely trust every action involved [2]. When the agent wants a site, you get three answers: “Allow this action”, “Always allow actions on this site”, and “Decline” [2]. Access granted this way can be revoked later, since “Users can grant or revoke Claude’s access to specific websites at any time in the Settings” [1].
Treat “always allow” as the decision it is. It is not a way to dismiss a dialog, it is a standing grant on a domain, and the honest default is to reserve it for sites where the worst available action is embarrassing rather than expensive. Once a quarter, open that list and delete everything you cannot immediately justify. Anthropic also blocks some categories outright, saying “we’ve blocked Claude from using websites from certain high-risk categories such as financial services, adult content, and pirated content” [1], which helps, but a blocklist written by a vendor cannot know which of your own domains hosts the button that cancels a client’s account.
If you have a Team or Enterprise plan, the admin controls move this from etiquette to policy. Admins can “Specify which sites Claude is permitted to access by adding them to the allowlist”, and a blocklist adds “an extra layer of protection beyond Claude’s default blocked categories” [4]. On the OpenAI side there is a blunter instrument. Lockdown Mode is “an optional advanced security setting that limits many tools and capabilities in OpenAI products that can connect to the web or external services”, disabling browsing, agent mode, downloads and other outbound paths, and it is aimed at people who “handle sensitive data and want stricter protection from data exfiltration risks related to prompt injection” [6]. Individual accounts turn it on under Settings, and workspace admins can assign it as a role [6].
Spend your approvals on the actions that cannot be undone
Approval prompts fail in a predictable way. The first ten get read, the next hundred get clicked, and by the second week you are approving whatever appears because the flow of work is on the other side of the button. So decide in advance which actions are worth the interruption, and let the rest run.
The vendors have drawn a first line for you. Claude asks before high-risk actions “like publishing, purchasing, or sharing personal data” [1], and even on a site you have granted standing permission it still stops for downloading files, entering sensitive information and granting authorisations [2]. The permissions guide also lists things it will not do at all, including making purchases or financial transactions, creating accounts, handling credit card or ID data, permanent deletions, and completing instructions that arrive from emails or web content [2]. That last item is the injection defence stated as a rule, and it is the one an attacker is trying to argue around.
Your own line goes further, because you know which of your buttons are irreversible. Anything that sends mail to a client, publishes to a live site, touches billing, or deletes rather than archives stays manual permanently. For a new workflow, run in manual mode for the first week and watch what the agent does when a page does not match its plan, then move to automatic once you have seen it fail cleanly. And keep one behavioural tripwire in mind. Anthropic’s guidance is to stay alert if “Claude suddenly starts discussing unrelated topics” [3], which is what an injected instruction often looks like from the outside: a competent assistant that abruptly develops a new agenda.
The mitigations are real and the residual is not zero
Give the vendors credit for measuring this and publishing the numbers. Anthropic reported that browser use without its safety mitigations “showed a 23.6% attack success rate when deliberately targeted by malicious actors”, and that adding mitigations to autonomous mode “reduced the attack success rate of 23.6% to 11.2%” [1]. On a narrower challenge set of four browser-specific attack types, the mitigations “were able to reduce attack success rate from 35.7% to 0%” [1].
Now read those numbers the way you would read them about anything else you rely on. An 11.2% success rate against deliberate attack is a large improvement and is not a defence you would accept on a door. Anthropic says so directly: “The risk is not zero. Novel attacks may emerge that our evaluations didn’t cover” [3]. OpenAI attaches a similar caveat to its strongest setting, noting that Lockdown Mode “does not prevent prompt injections from appearing in the content ChatGPT processes” [6]. The mitigations reduce how often a hostile page wins. They do not change who the agent is acting as when it loses.
Your own volume and threat assumptions, with Anthropic's post-mitigation attack success rate of 11.2% as the default [1]. An order-of-magnitude estimate, not a forecast. Computed in the page; nothing is sent anywhere.
What still goes wrong
The largest unsolved piece is the one nobody markets. There is no widely available, plain reading of what your agent did in the browser last Tuesday. Anthropic’s admin documentation for Claude in Chrome covers extension availability, allowlists and blocklists [4]; a per-action history you can hand to a client after an incident is a different artefact. In practice, your reconstruction is the site’s own audit log, which means the small operator’s real logging strategy is to use the agent only in places that keep their own record of who changed what.
The second problem is that the safe configuration and the useful one pull in opposite directions. An agent locked out of your logged-in tools cannot do the work that made you want it. Lockdown Mode illustrates the trade honestly by turning off browsing, agent mode and downloads together [6], and OpenAI’s roadmap for browser agents runs the other way, toward “account login support” in an extension inside your ordinary browser [5]. Even the invocation model is drifting. Gemini in Chrome “activates only when you choose to use it via clicking on the Gemini icon or the keyboard shortcut you set up” [7], which is a real boundary, and also one that a single default change could move.
The third is that published attack rates are measured against attacks that were already imagined. A challenge set reduced to 0% [1] is evidence that a known class of attack was closed, not that the category is finished, and a technique that works will be reused against whatever the current defaults happen to be. Nothing here makes browser agents safe. It makes them bounded, which is the strongest claim available at the moment, and it is enough to use one for a real task tomorrow morning as long as the account list behind it is short and you chose every name on it.
- 01Anthropic — Claude for Chromeclaude.com
- 02Anthropic Help Center — Claude in Chrome permissions guidesupport.claude.com
- 03Anthropic Help Center — Use Claude in Chrome safelysupport.claude.com
- 04Anthropic Help Center — Claude in Chrome admin controlssupport.claude.com
- 05OpenAI Help Center — Evolving Atlas into ChatGPT for browser-based agentic workhelp.openai.com
- 06OpenAI Help Center — Lockdown Modehelp.openai.com
- 07Google — Gemini in Chrome overviewgemini.google
- 08Brave — Comet prompt injection researchbrave.com