A Claude task jumped to a second person's computer

Chrome windows kept opening on a machine whose owner had not asked Claude for anything, and the tabs were product pages his partner was researching from a different computer. The account comes from a July 30, 2026 post on Braw, written by one half of a couple who share a single Claude Pro account.
At a glance
- Both run Claude Desktop with the Claude for Chrome extension installed, share one Claude Pro account, and neither switched on remote control, the Computer use preview or Claude Code on the web.
- When his partner's Chrome was closed, the author writes, the browsing turned up on his machine instead, with nothing on screen marking the switch; he found the tabs by accident.
- The post is one household's observation: no logs, no timestamps, no word on which Claude surface issued the clicks or what picked the second computer, and the experiments are still running.
If you have not been following, Claude stopped living only in a chat window a while back. The desktop app, Claude Code and the browser extension all hand it the ability to act on a machine rather than tell you what to click, and this story sits on top of that stack.
Claude for Chrome opened shopping tabs on the wrong laptop
The author writes that his partner was doing shopping research with Claude. On his machine, Chrome windows opened on their own and navigated to sites for the products his partner was looking at. Both of them are software engineers, so they dug in: on the occasions when the partner's Chrome was closed, the work appeared to move to the other machine, with nothing on screen saying so.
He noticed only because Chrome is not his daily browser. It usually sits in the background and he rarely touches it, so he found the open tabs by accident while clearing out old windows.
Neither account holder switched on remote control or Computer use
Both machines run Claude Desktop with the Claude for Chrome extension installed and configured, and the two share one Claude Pro account. That, the author stresses, is the whole setup: neither of them opted into Claude's remote-control features, the Computer use preview, or Claude Code on the web.
They are now trying to block the tool on one machine to see whether Claude, and Claude Code in particular, switches to the other. If it does, he writes, they will rethink the workflow, because unmitigated remote access to a machine that is not your own is an uncomfortable thing to have running.
His warning is aimed at anyone whose Claude seat is shared with people they trust less, or sold on to strangers for credits. In his case it was only his partner, but he argues a shared or resold seat can put your own digital safety and privacy at risk.
What does Claude in Chrome actually get to do?
Anthropic describes Claude in Chrome as an extension that reads, clicks and navigates pages alongside you, launched from the Chrome side panel or through Claude Cowork or Claude Code. When a chat or a task touches a website, the company says, Claude can open Chrome directly and do the work itself, typing, clicking and filling in forms the way a person would, without you switching windows.
The permission behind that is Chrome's debugger access, which Anthropic calls what allows Claude to actually control your browser when you ask it to complete a task. Think of it less as a plugin reading the page and more as a second pair of hands on your own mouse.
The side panel also starts in Automatically approve mode, according to Anthropic: Claude works continuously and stops to ask only when an action needs approval, and if you switch the mode it remembers that choice. The company pitches the extension and Claude Code together as a build, test and verify loop for design checks, live debugging and automated testing.
A browsing agent reads instructions it was never meant to obey
Anthropic is blunt about the risk in browser agents. Prompt injection means hidden instructions buried in a page hijack what the agent does next, up to exfiltrating data; in the company's words, every webpage an agent visits is a potential vector for attack.
Two things make a browser harder to defend, by Anthropic's account. The attack surface covers every page, embedded document, ad and script the agent meets, and the agent can act on what it reads by opening URLs, filling forms, clicking buttons and downloading files.
Anthropic also says prompt injection is far from a solved problem, particularly as models take more real-world actions, and that it wants a future where agents handle high-value tasks without significant injection risk.
All of this rests on one household's observation. The post shows no logs and does not say which Claude surface issued the clicks, so we cannot tell whether a task was routed across devices or whether both desktops were simply live under one session. In our view the uncomfortable part is the default the author describes: browsing that ran on his machine with no sign of it on that machine.
What the blocking test could show
The experiments were still under way when the post went up on July 30, 2026, and it carries no results, so whether blocking the extension on one machine pushes Claude or Claude Code onto the other stays open. If you share a seat with someone, the cheap check is the one that caught this in the first place: open the browser you never use and look at the tabs.
Related stories
- A Claude exploit quietly exfiltrated a user's name and employer
- Claude Code user reports another tenant's credentials leaking between sessions
- Claude Desktop turned into a C2 agent via configuration poisoning
- Claude's mobile app is getting account switching
- Anthropic will bill again for requests its safeguards block
- Anthropic's 225 bug finds, one attack in the wild
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
