Skip to content
Writing
By MD Jehad H.··4 min read·Explainer

ChatGPT browser extensions arrive: what to check first

Drafted through my n8n + AI pipeline, edited by me.

OpenAI's ChatGPT desktop app now runs Chrome extensions inside its built-in browser, so the assistant can click through tabs, fill forms, and work next to tools like a password manager without you leaving the chat window.

The change landed on September 18 and applies to the browser embedded in the ChatGPT desktop app on Mac and Windows, not your regular Chrome window. That built-in browser keeps its own cookies, logins, and extensions instead of borrowing the profile you already use, so anything you install there starts from a blank slate.

What actually changed in the desktop app

Before this update, the agent browser could open pages and act on them, but it couldn't run the extensions people actually rely on: password managers, ad blockers, form fillers. Now you can install and pin those extensions the same way you would in a normal Chrome tab, and the agent can browse alongside them. For a service business that means the assistant can log into a client portal through a saved password, pull a report, or fill out a recurring form without someone typing credentials into a chat box.

What ChatGPT browser extensions can and cannot see

  • The agent cannot read data inside your extensions or reach into a page's shadow DOM, which is the boundary meant to stop it from lifting saved passwords or session tokens.
  • New websites require your approval before the agent will act on them, one site at a time.
  • The built-in browser does not import your everyday Chrome profile, cookies, or history by default.
  • Workspace and enterprise admins can turn the whole browser off, limit which sites it reaches, or block cookie and password imports entirely.

Table of four ChatGPT browser controls, their default state, and what each means for a small business

ControlDefault stateWhat it means for you
New site accessRequires approval each timeAgent can't act on a site you haven't cleared
Extension dataIsolated by designAgent can't read what's inside your password manager or other extensions
Chrome profileNot inheritedSeparate cookies and logins from your daily browser
Admin consoleBrowser on by defaultAdmins can disable it, restrict sites, or block imports
The defaults lean cautious, but only an admin who checks the console knows what is actually turned on.

What to check before anyone on your team turns this on

  1. 1

    Check your plan and admin console

    If you're on a ChatGPT Business or Enterprise plan, log into the workspace admin settings and see whether the desktop browser is currently on, off, or restricted.

  2. 2

    Decide who actually needs it

    This is most useful for repetitive, logged-in tasks: pulling reports from a client portal, checking a dashboard, filling the same web form. Turn it on for those people, not the whole team by default.

  3. 3

    Set the site-approval habit

    Tell whoever uses it to actually read the approval prompt before clearing a new site, the same way they'd read a permissions request on their phone.

  4. 4

    Watch what flows through it for the first week

    Spot-check what the assistant touched and on which sites before you treat this as routine.

This is a product boundary, not an audit

OpenAI describes the extension isolation as intentional, but it's a design decision from the vendor, not an independent security review. Treat anything the agent reads on an unfamiliar site as untrusted, and type credentials into the browser yourself instead of pasting them into chat.

If your team is already running ChatGPT day to day and someone wants this switched on, it's worth five minutes in the workspace admin settings before you say yes. Happy to look at your setup with you if you want a second opinion on what to lock down first.

Building something this should run inside?

Book a systems call

Keep reading