Chrome Extensions Inside ChatGPT: OpenAI Turns Its Desktop App Into a Real Browser Platform
OpenAI's September 18 desktop update lets users install and pin Chrome extensions in ChatGPT's built-in browser, ships ChatGPT for Word to general availability, adds multi-account plugins, and brings Appshots to Windows — with strict enterprise controls around agent access.
On September 18, OpenAI product lead James Sun announced one of the most consequential product changes ChatGPT has received in months: the ChatGPT desktop app’s built-in browser now supports Chrome extensions. Users can install, pin, and use their everyday extensions — 1Password, password managers, ad blockers, developer tools — without ever leaving the AI assistant. It arrived not as an isolated feature but as part of a coordinated batch of desktop and plugin updates that also brought ChatGPT for Word to general availability, multi-account plugin connections, and Appshots on Windows.
Individually, each item reads like routine shipping. Together, they sketch a deliberate strategy: OpenAI is converging ChatGPT toward becoming a full working environment — the place where browsing, documents, credentials, and now browser extensions live side by side with the model itself.
What Shipped on September 18
Chrome extensions in the built-in browser. The headliner. The ChatGPT desktop app ships with an embedded Chromium-based browser that keeps tasks inside the app, and it maintains its own browser state, separate from a user’s Chrome profile. As of this update, that browser accepts standard Chrome Web Store extensions. Sun’s example was 1Password — a telling choice, because password managers are the extension category users miss most when they leave Chrome.
There are boundaries. OpenAI’s documentation draws a sharp line between the in-app browser and the Codex Chrome extension: use the built-in browser for local development, public pages, and tasks you want to keep inside the app; use the Chrome extension when a task genuinely needs your existing Chrome profile, signed-in sessions, open tabs, or your full extension set. The in-app browser is a sandbox with a door, not a Chrome clone.
ChatGPT for Word reaches general availability. After a lengthy preview, the Microsoft Word add-in is now broadly available. It puts drafting, summarizing, revising, and formatting in a sidebar inside Word, governed by the same ChatGPT account and usage limits. For the enormous population of knowledge workers whose day is structured around Office documents, ChatGPT now lives where the work happens rather than a tab away.
Multi-account plugins. ChatGPT plugins can now connect multiple accounts, expanding beyond the original Gmail, Google Calendar, and Google Contacts trio. A user juggling personal and work inboxes, or an assistant acting across several organizational calendars, no longer has to pick a single connection per plugin.
Appshots on Windows. Windows users get a faster path to give the model visual context: Appshots captures a screenshot plus available text from the frontmost application and drops it into the conversation. It is a small feature that compounds — multimodal input friction is one of the remaining seams in daily AI use.
The Enterprise Controls Matter More Than the Feature
The most interesting details in the announcement are the ones directed at administrators. OpenAI explicitly walls the ChatGPT agent off from extension DOM and data — extensions run in the browser context, but the agent operating the browser does not automatically gain access to what extensions can see. Enterprise admins can disable the in-app browser entirely, restrict which sites it may visit, block credential imports, and enforce policies that end users cannot override.
That last clause is doing real work. The entire promise of agentic AI in the enterprise depends on IT departments believing they retain a kill switch at every layer. By making browser, extensions, credentials, and agent access separately controllable, OpenAI is telling CIOs that adopting ChatGPT as a workspace does not mean surrendering governance.
It also reflects a lesson the industry has learned the hard way in 2026. This was the week researchers disclosed Plugin4Shell, a zero-click remote code execution flaw affecting the plugin systems of Claude Code, Codex, GitHub Copilot, and Gemini CLI — a reminder that every new extensibility surface is also a new attack surface. OpenAI’s decision to keep the agent fenced away from extension data, and to give admins granular overrides, reads as a direct response to that climate.
Why This Is Bigger Than a Changelog Item
There are two ways to read the trajectory.
The narrow reading: OpenAI is reducing friction. Users told OpenAI they hate switching windows, re-logging into sites, and copy-pasting between apps. Extensions, Word integration, multi-account plugins, and Appshots each remove one instance of that friction.
The broader reading: OpenAI is competing to own the workspace layer itself. If ChatGPT is where you browse, where your password manager lives, where your Word documents get written, and where your accounts are connected — the marginal cost of leaving the OpenAI ecosystem rises with every feature. This is the same playbook that made browsers, then mobile operating systems, the strategic high ground of earlier platform eras: own the environment, and the applications — here, the models — follow.
The competitive context makes the timing pointed. Anthropic’s Claude Code and Cowork have been consolidating enterprise traction, and reports this week put Anthropic on pace for over $100 billion in annualized revenue. Google’s Gemini ecosystem spans the world’s most-used browser and office suite. Microsoft — simultaneously OpenAI’s partner and its most embedded rival — just received ChatGPT inside Word while its own Copilot watches from the adjacent ribbon. Every frontier lab now treats the desktop as contested territory, and OpenAI just moved several pieces onto that board at once.
The Security Trade-Off Nobody Should Ignore
Extensions are also one of the largest attack surfaces in consumer software. Chrome extension ecosystems have historically struggled with malicious add-ons, supply-chain compromises, and over-broad permissions. Bringing that ecosystem inside an AI assistant that can act on what it sees multiplies the stakes: a compromised extension no longer just exfiltrates data, it potentially influences an agent with access to your accounts.
OpenAI’s architectural answer — extensions in the browser context, agent fenced off from extension DOM and data, admin-enforceable policies — is a reasonable start, and materially more cautious than simply embedding Chrome wholesale. But the burden of proof now shifts to sustained execution: prompt-injection defenses, extension vetting, and audit trails will determine whether this convenience becomes a liability. Enterprises rolling this out should pair it with the same scrutiny they apply to browser management today, not less.
What to Watch
Three signals will tell us whether this batch of updates was a milestone or a footnote. First, adoption of the in-app browser as a daily driver rather than a novelty — extension support is the feature most likely to convert skeptics. Second, whether third-party developers begin treating ChatGPT’s browser as a target platform, optimizing extensions for an AI-adjacent context. Third, whether the enterprise controls survive contact with real deployments, or get quietly weakened in the name of engagement.
What is already clear is the direction. ChatGPT began as a chat window. It is ending the month as an environment — documents, browser, credentials, extensions, and an agent that ties them together. The chat window was never the product; it was the on-ramp.
Sources
- [1] https://x.com/JamesZmSun/status/2100995281097769216
- [2] https://help.openai.com/en/articles/20001277-using-the-built-in-browser-in-the-chatgpt-desktop-app
- [3] https://www.neowin.net/news/chatgpt-finally-comes-to-microsoft-word-gets-new-google-chrome-extension-and-more/
- [4] https://runtimewire.com/article/openai-chatgpt-desktop-browser-chrome-extensions
- [5] https://help.openai.com/en/articles/6825453-chatgpt-release-notes