BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Claude Cowork bug lets AI break sandbox, access Mac files

Sandbox escape in Anthropic's Claude Cowork exposes 500,000 Mac users to full filesystem access.

  • Researchers at Accomplish AI discovered a sandbox escape vulnerability in Anthropic‘s Claude Cowork, affecting approximately 500,000 macOS users.
  • The flaw, named SharedRoot, allowed an agent to break out of a Linux VM and access the entire host Mac filesystem with read-write privileges.
  • Anthropic closed the report as informative without a fix, but the latest version defaults to cloud execution; local sessions remain vulnerable.

Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic‘s Claude Cowork that allows an agent to break out of a Linux virtual machine and read or write files anywhere on a Mac. Accomplish AI, which shared details with The Hacker News, said about 500,000 macOS users running local Cowork sessions were affected before it was patched in a vulnerability codenamed SharedRoot.

- Advertisement -

“We connected a folder to a fresh Claude Cowork session, sent one short message, and watched the agent escape the sandbox,” said Oren Yomtov, principal security researcher at Accomplish AI. From inside the VM, the agent reached the host Mac and accessed files far outside the connected folder without any permission prompt. Consequently, the agent could access any data stored on the Mac, including SSH keys and cloud credentials.

The desktop app runs as the logged-in user, while agent work happens in a Linux VM created via Apple’s Virtualization framework. Every session gets its own disposable user and a seccomp filter, but the host filesystem is shared into the VM read-write by a root daemon called coworkd. “The entire host ‘/,’ mounted so that only guest-root inside the VM can see it, at /mnt/.virtiofs-root,” Yomtov explained.

The exploit involves loading the Linux kernel’s act_pedit subsystem into an unprivileged user namespace and exploiting CVE-2026-46331, a flaw called pedit COW, to obtain guest-root. Accomplish AI CTO Or Hiltch noted that creating user and network namespaces gives the session CAP_NET_ADMIN within its private network namespace. “That capability provides access to the vulnerable tc/act_pedit kernel path used by pedit COW,” Hiltch added.

The development follows revelations that OpenAI’s models broke out of their sandboxed environment during a security test, breaching Hugging Face’s production infrastructure. “act_pedit is one bug in a category,” Yomtov stated, noting that the Linux net/sched subsystem regularly produces privilege escalation bugs. “Patch this one and you’ve fixed this one. The chain re-arms on the next one.”

- Advertisement -

To mitigate the threat, Accomplish AI recommends disabling unprivileged user namespaces and restricting host sharing to only connected folders. “Scope it to the folders that were actually connected instead of all of /, or at least mount it read-only,” the firm said.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tesla needs marketing push for robotaxis, Optimus: Fund manager

Future Fund Managing Partner Gary Black argues Tesla needs a long-term marketing strategy, not...

SEC Clears Franklin Templeton to Invest in Onchain Money Fund

The SEC issued a no-action letter allowing Franklin Templeton funds to invest in its...

SharePoint CVE-2026-55040 exploited after PoC release

Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040, CVSS 9.1) after...

Bernstein Hikes Microsoft Target to $660, Bullish on AI

Bernstein raised its Microsoft (MSFT) price target from $647 to $660, maintaining an outperform...

Bitwise: Crypto valuations could double on buybacks, burns

Bitwise CIO Matt Hougan argues crypto valuations could at least double as protocols route...

Must Read

Top 10 BEST Crypto Trading Books for New Traders

If you're thinking of diving into the crypto trading space, acquiring solid knowledge isn't just recommended - it's essential to protect your investment.Learning...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading