Cowork Can Use a Chrome Instance on Another Machine Without You Knowing

A Reddit user testing Cowork on Linux asked it to search booking.com. Cowork requested Chrome permission, but Chrome wasn't installed on the Linux machine. When confronted, the Claude-powered assistant admitted the browser connected was flagged isLocal: false — meaning the Chrome instance with the Claude in Chrome extension was on a Windows device elsewhere (authenticated via Anthropic account). The user later confirmed the open tab on their Windows desktop.
Key technical detail: the assistant stated the connected browser appears as isLocal: false, indicating it's not on the current machine. The extension must be installed and paired via the same Anthropic account on the remote machine, and that browser must be left running.
This behavior is not documented — the assistant itself couldn't find docs when asked. Developers using Cowork should be aware that permission prompts for browser use may refer to a remote Chrome instance. To see the actual browser tab, you need to be physically at the machine where the extension is paired.
This is a significant privacy/routing consideration: the AI agent can transparently use a browser on another machine without explicit user awareness that the browser is remote. The user wasn't gaslit — the assistant simply misidentified the browser's location initially.
Who this affects
Anyone using Cowork (or similar AI agents with browser use) across multiple machines with the same Anthropic account. Check which machine has the paired extension and is currently running Chrome.
📖 Read the full source: r/ClaudeAI
👀 See Also

China Blocks Meta's Acquisition of AI Startup Manus
China's government blocked Meta's proposed acquisition of AI startup Manus, citing national security concerns. The deal was reportedly valued at over $1 billion.

Claude-Code v2.1.80 adds rate limit monitoring, plugin improvements, and memory optimizations
Claude-Code v2.1.80 introduces a rate_limits field for statusline scripts to display Claude.ai usage, adds source: 'settings' plugin marketplace support, and reduces memory usage by ~80 MB in large repositories. The release also fixes parallel tool result restoration, WebSocket failures, and various UI issues.

OpenClaw 5.4 Adds /steer and /side Commands: Redirect Agent Mid-Task Without Losing Context
OpenClaw 5.4 introduces /steer and /side commands that let you redirect an agent's current task direction or start a side conversation without losing session context.

OpenRouter's Healer Alpha stealth model appears to be unreleased Qwen 3.5-Omni variant
OpenRouter has deployed a free anonymous omni-modal model called Healer Alpha with 262,144 context window and multimodal capabilities. Forensic analysis suggests it's an unreleased Qwen 3.5-Omni variant from Alibaba.