ChatGPT browser extensions arrive: what to check first
Drafted through my n8n + AI pipeline, edited by me.
OpenAI's ChatGPT desktop app now runs Chrome extensions inside its built-in browser, so the assistant can click through tabs, fill forms, and work next to tools like a password manager without you leaving the chat window.
The change landed on September 18 and applies to the browser embedded in the ChatGPT desktop app on Mac and Windows, not your regular Chrome window. That built-in browser keeps its own cookies, logins, and extensions instead of borrowing the profile you already use, so anything you install there starts from a blank slate.
What actually changed in the desktop app
Before this update, the agent browser could open pages and act on them, but it couldn't run the extensions people actually rely on: password managers, ad blockers, form fillers. Now you can install and pin those extensions the same way you would in a normal Chrome tab, and the agent can browse alongside them. For a service business that means the assistant can log into a client portal through a saved password, pull a report, or fill out a recurring form without someone typing credentials into a chat box.
What ChatGPT browser extensions can and cannot see
- The agent cannot read data inside your extensions or reach into a page's shadow DOM, which is the boundary meant to stop it from lifting saved passwords or session tokens.
- New websites require your approval before the agent will act on them, one site at a time.
- The built-in browser does not import your everyday Chrome profile, cookies, or history by default.
- Workspace and enterprise admins can turn the whole browser off, limit which sites it reaches, or block cookie and password imports entirely.
Table of four ChatGPT browser controls, their default state, and what each means for a small business
| Control | Default state | What it means for you | |
|---|---|---|---|
| New site access | Requires approval each time | Agent can't act on a site you haven't cleared | |
| Extension data | Isolated by design | Agent can't read what's inside your password manager or other extensions | |
| Chrome profile | Not inherited | Separate cookies and logins from your daily browser | |
| Admin console | Browser on by default | Admins can disable it, restrict sites, or block imports |
What to check before anyone on your team turns this on
- 1
Check your plan and admin console
If you're on a ChatGPT Business or Enterprise plan, log into the workspace admin settings and see whether the desktop browser is currently on, off, or restricted.
- 2
Decide who actually needs it
This is most useful for repetitive, logged-in tasks: pulling reports from a client portal, checking a dashboard, filling the same web form. Turn it on for those people, not the whole team by default.
- 3
Set the site-approval habit
Tell whoever uses it to actually read the approval prompt before clearing a new site, the same way they'd read a permissions request on their phone.
- 4
Watch what flows through it for the first week
Spot-check what the assistant touched and on which sites before you treat this as routine.
This is a product boundary, not an audit
OpenAI describes the extension isolation as intentional, but it's a design decision from the vendor, not an independent security review. Treat anything the agent reads on an unfamiliar site as untrusted, and type credentials into the browser yourself instead of pasting them into chat.
If your team is already running ChatGPT day to day and someone wants this switched on, it's worth five minutes in the workspace admin settings before you say yes. Happy to look at your setup with you if you want a second opinion on what to lock down first.
Building something this should run inside?
Book a systems callKeep reading
ai agents
ChatGPT's sponsored agents are already selling your leads
OpenAI's sponsored agents let brands like Angi answer customer questions inside ChatGPT, ahead of your own site or call.
microsoft copilot
Copilot Autopilot needs a permissions check first
Microsoft's Copilot Autopilot agent can work while you're offline and bill by usage. Here's what to check before you turn it on.
ai pricing
Claude Opus 5.5 just cut your AI automation costs
Claude Opus 5.5 costs about 40 percent less to run than its predecessor. Here is how to check whether your automations actually benefit.