Sunday, September 13, 2026

Claude AI Can Now Control macOS and Windows Computers to Click, Type and Open Apps

Anthropic has enhanced Claude’s desktop automation capabilities, enabling the AI assistant to operate directly on macOS and Windows computers through Claude Cowork and Claude Code.

When this feature is enabled, Claude can navigate a visible screen, click controls, type text, launch applications, open files, and work within browser-based or local tools if no dedicated connector is available.

This beta feature is accessible to Pro and Max subscribers in the Claude Desktop application. It transforms Claude from a chat-based assistant into an agent capable of executing tasks across the desktop, while also introducing important security, privacy, and governance considerations for organizations adopting daily workflows.

Claude AI Control macOS and Windows Computers

Claude Cowork follows a hierarchy that prioritizes precision and speed. It first attempts to use connected services such as Gmail, Google Drive, Microsoft 365, or Slack since connectors can handle information retrieval or actions more reliably than visual navigation.

If no suitable connection exists, Claude can use the desktop app’s built-in browser or Google Chrome through Claude in Chrome. Screen interaction is the last resort: the model examines the interface and performs actions as a human would.

This method allows Claude to work within internal dashboards, specialized software, development environments, and applications that lack integrations. However, it is generally slower and more error-prone.

On macOS 15 and later, Claude can operate in background windows, allowing users to continue using their computer while the agent runs.

Anthropic states that Claude typically does not take control of the pointer or keyboard and will wait when it detects active typing; it requests permission before requiring full-screen control during the first session.

Users can also select a full-control setting in the desktop app’s General preferences. On both operating systems, each application needs approval before Claude can interact with it.

The vendor blocks certain applications by default and provides an app blocklist, allowing users to deny access to specific software or sensitive workflows.

From a cybersecurity standpoint, this feature creates a high-value permission boundary between the AI agent and the user’s desktop. Claude takes screenshots to understand interfaces and can view any content visible in applications, including sensitive documents and third-party data.

Anthropic warns that there is no sandbox feature between the model and applications. Although the company claims that Claude is trained to avoid sensitive data entry, facial-image scraping, and investment transactions, it acknowledges that its safeguards are not foolproof.

It scans for prompt-injection indicators during computer use. It seeks user permission before accessing any apps, but attackers may exploit on-screen content or links.

Anthropic recommends starting with research or organizational tasks, crafting precise prompts, closely monitoring execution, and avoiding access to banking, healthcare, government, legal, financial, or other apps containing personal data.

Users should close sensitive files and applications before enabling the feature, as screenshots may capture all visible content in those contexts.

Computer use requires that the desktop and the Claude Desktop app be open, and complex workflows may require multiple attempts. This beta feature is not available to Team and Enterprise plans.

For security teams, this rollout highlights an essential principle: the convenience of an AI agent must be balanced with least privilege, oversight, controls, and thorough threat modeling before deployment.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News