Claude anthropologists for chrome in Beta is limited, but immediate injection attacks are still a major concern

Photo of author

By [email protected]


Want more intelligent visions of your inbox? Subscribe to our weekly newsletters to get what is concerned only for institutions AI, data and security leaders. Subscribe now


man A test started Chrome browser extension This allows the Claude Ai to control user web browsers, which represents the company’s entry into an increasingly crowded and perhaps risky yard where artificial intelligence systems can deal directly with computer facades.

The San Francisco Imported Intelligence Company announced on Tuesday that it will take place.Claude Chrome“With the presence of 1000 reliable users in his MAX plan, the status mode has developed as a research inspection designed to address the important security weaknesses before the broader publication. The cautious approach contradicts more aggressive moves by the competitors Openai and MicrosoftWho have already released similar artificial intelligence systems that control the computer to wider user bases.

This announcement confirms the rapid transformation of the artificial intelligence industry from developing chat groups that simply respond to questions towards the creation of “agent” systems capable of completing complex and multi -step tasks independently through software applications. This development represents what many experts consider the following limits in artificial intelligence – and perhaps one of the most profitable, as companies are racing to automate everything from expenses reports to vacation planning.

https://www.youtube.com/watch?

How can artificial intelligence scientists control your browser, but the hidden malicious code pose serious security threats

Claude Chrome Users, under the guidance of artificial intelligence, are allowed to conduct procedures on their behalf inside web browsers, such as scheduling meetings by verifying calendars and the availability of reference restaurants, or managing e -mail funds and dealing with routine administrative tasks. The system can see what is displayed on the screen, click the buttons, fill the models, and move between web sites-mainly simulates how humans interact with the web-based programs.


Artificial intelligence limits its limits

Power caps, high costs of the symbol, and inference delay are reshaped. Join our exclusive salon to discover how the big difference:

  • Transforming energy into a strategic advantage
  • Teaching effective reasoning for real productivity gains
  • Opening the return on competitive investment with sustainable artificial intelligence systems

Securing your place to stay in the foreground: https://bit.ly/4mwngngo


“We look at the use of AI as an inevitable matter: a lot of work occurs in browsers so that Claude gives the ability to see what you look, and the clicks buttons, and will make packing models much more useful,” Antarbur said in its announcement.

However, the internal test of the company has been revealed with regard to security weaknesses that highlight the two -boundary nature of giving artificial intelligence systems direct control of the user’s facades. In hostilities, Anthropor found that malicious actors can guarantee hidden instructions on websites, emails or documents to deceive artificial intelligence systems in harmful measures without knowing users – a technology called fast injection.

Without safety reduction, these attacks succeeded at 23.6 % of the time when Amnesty International intentionally targets the browser. In one examples, request the harmful email in which Claude guidance to delete the user’s emails “for the mailbox hygiene”, which AI was implemented without confirmation.

“These are not speculation: we have operated” red “experiences to test Claude for chrome, and without relieving, we found some related results.

Rush Openai and Microsoft Rush for Marketing while Antarbur takes a measurable approach to computer control technology

The scalp approach comes from Antarbur, as the competitors moved more strongly to the computer control space. Openai launched the “operator” agent In January, which makes it available to all Chatgpt Pro users of $ 200 per month. Supported by a new model “Computer Use Using”, the operator can perform tasks such as reserving concert tickets, grocery order, and planning travel paths.

Microsoft followed in April with the possibilities of using the computer built into Copilot Studio PlatformTargeting institutional customers using user interface automation tools that can interact with both web applications and desktop programs. The company has put its display as an alternative to the next generation of traditional automation automation systems (RPA).

Competitive dynamics reflects broader tensions in the industrial intelligence industry, as companies must balance pressure to charge advanced capabilities against the risk of spreading technology that has been adequately tested. The most aggressive schedule of Openai allowed its share in the early market, while the hotropic cautious approach may limit its competitive position but it may be useful if safety concerns are achieved.

Anthropor pointed out that “the factors of the use of the browser are supported by border models already appear, which makes this work in particular”, which indicates that the company feels that it is obliged to enter the market despite the safety problems that have not been solved.

Why can you control the computer intelligence computer to automate institutions and replace expensive workflow programs

The emergence of artificial intelligence systems that mainly control the computer can re -treat automation and workflow management. The automation of the current institution usually requires expensive customized complementarity or automation automation programs that collapse when applications change their interfaces.

Computer use agents in a democratic nature of automation by working with any program that has a graphical user interface, which may lead to automation of tasks through the widespread ecosystem of business applications that lack official applications or integration capabilities.

Salsforce researchers recently showed this capabilities with Coact-1 systemWhich combines traditional automation to click and click with the possibilities of generating the code. The mixed approach has achieved a success rate of 60.76 % on complex computer tasks while asking for a much lower steps than the factors based on the graphic user interface, indicating that great efficiency gains are possible.

“For institution leaders, the key lies in automating multi -roofing complex operations as full access to the API programming interface (API) is a luxury, not a guarantee,” explained by Ran Show, the director of applied artificial intelligence research in Salesforce, pointing to the course of customer support that extends to multi -royal systems as cases for main use.

University researchers launched a free alternative to artificial intelligence systems to use the Big Tech computer

The dominance of property systems from major technology companies prompted academic researchers to develop open alternatives. Hong Kong University has been released recently OpenCUAAn open source working framework for training computer use agents that compete with OpenAi and Anthropor’s royal models.

the OpenCUA systemHe was trained on more than 22,600 human task demonstrations via Windows, MacOS and Ubuntu, which have achieved newer results between open source models and competitive performance with leading commercial systems. This development may accelerate the adoption of companies that are reluctant to rely on closed systems for the functioning of critical automation.

The Antarbur safety test reveals that artificial intelligence agents can be deceived in deleting files and stealing data

Antarbur carried out several layers of protection Claude ChromeIncluding site permits that allow users to control web sites that artificial intelligence can reach, mandatory assurances before severe risk procedures such as purchases or personal data sharing, and prohibiting access to categories such as financial services and adult content.

The company’s safety improvements have reduced the success rates of instant injection attack from 23.6 % to 11.2 % in independent mode, although CEOs admit that this is still not enough to publish on a large scale. On the browser attacks that involve hidden shape fields and URL, new reductions have reduced the success rate from 35.7 % to zero.

However, this protection may not expand to the complete complexity of the real world’s web environments, as the new attack tankers continue to appear. The company plans to use visions of the experimental program to improve its safety systems and develop more advanced controls.

“New forms of immediate injection attacks are constantly developed by harmful actors,” Antarbur warned, highlighting the continuous nature of the security challenge.

Artificial intelligence factors can be re -clicked mainly how people interact with computers

The multiple major AI’s rapprochement around computer control agents indicates a major shift in how artificial intelligence systems interact with the infrastructure of current programs. Instead of asking companies to adopt new, special tools of artificial intelligence, these systems are working with any applications that companies already use.

This approach can significantly reduce the barriers that prevent the adoption of artificial intelligence with the displacement of traditional automation sellers and system integration. Companies that have invested extensively in customized integration operations or RPA platforms may find their approaches that are surpassed by artificial intelligence agents for general purposes that can adapt to interface changes without reprogramming.

For institutional decision makers, technology provides opportunity and risk. The first trap can gain great competitive advantages through improved automation capabilities, but the security weaknesses shown by companies such as anthropor indicate that caution may be justified until safety measures are ripe.

Limited pilot from Claude Chrome Just the beginning of what industrial observers expect to be a rapid expansion of the possibilities of artificial intelligence to control the computer through the technology scene, with repercussions that go beyond the automation of the simple task to the basic questions about the interaction of human stiffness and digital security.

Anthropor also noticed in its announcement: “We believe that these developments will open new possibilities for how you work with Claude, and we look forward to seeing what you will create.” Whether these possibilities ultimately prove useful or problem that may depend on the success of the industry with the security challenges that have already begun to appear.



https://venturebeat.com/wp-content/uploads/2025/08/nuneybits_a_simple_hand-drawn_illustration_of_an_open_web_page__c908bef6-37a0-486e-bcb2-59cef9c8c501.webp?w=1024?w=1200&strip=all
Source link

Leave a Comment