Browser AI is heating up—but security cracks are widening faster than features ship
When did browser extensions become a security liability instead of a convenience? That's the question facing users as Anthropic's Claude for Chrome extension faces serious vulnerabilities, despite the company allegedly alerting Anthropic multiple times about the risks. Security experts warn the bypass is "still six lines of JavaScript"—a damning indictment of how quickly AI tools are shipping without hardening against attack. The extension integrates Claude directly into Chrome's interface, but the exploit window suggests the convenience-first approach is leaving users exposed.
Meanwhile, Arc Search is taking the opposite path: leaning harder into AI rather than pulling back. The browser's search experience now centers on AI-generated summaries and insights, positioning itself as the native alternative to bolting extensions onto Chrome. Where Claude for Chrome bolts an AI assistant onto an existing browser, Arc bakes it into the core product. It's a philosophical split—one treating AI as an add-on layer, the other as foundational.
The timing matters. We're seeing a broader pattern this year where hardware gets more repairable and ports return to flagships, yet software is racing toward centralized AI dependencies. Smartphone releases reflect this tension: the Redmi Note 17 Pro and Nothing Phone (both currently discounted) emphasize practical specs and durability, while the iPhone Air at £200 off signals Apple's mid-tier ambitions. OnePlus's European and North American exit removes another option for consumers seeking alternatives.
For gadget buyers, the tradeoff is becoming clearer. Arc Search offers integrated, designed-from-scratch AI search. Claude for Chrome promises flexibility but currently delivers risk. The extension ecosystem is fragmented, and security reviews lag feature velocity. Using either means accepting different threat models: the convenience of native tools versus the openness of modular extensions.
Until Claude's vulnerabilities close—and the industry settles on safer extension standards—Arc's integrated approach looks less like a gimmick and more like a realistic answer to the question of how to ship AI safely at scale.
See the latest aggregated gadgets headlines on AI Feeds, updated continuously throughout the day.