BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Claude Cowork bug lets AI break sandbox, access Mac files

Sandbox escape in Anthropic's Claude Cowork exposes 500,000 Mac users to full filesystem access.

  • Researchers at Accomplish AI discovered a sandbox escape vulnerability in Anthropic‘s Claude Cowork, affecting approximately 500,000 macOS users.
  • The flaw, named SharedRoot, allowed an agent to break out of a Linux VM and access the entire host Mac filesystem with read-write privileges.
  • Anthropic closed the report as informative without a fix, but the latest version defaults to cloud execution; local sessions remain vulnerable.

Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic‘s Claude Cowork that allows an agent to break out of a Linux virtual machine and read or write files anywhere on a Mac. Accomplish AI, which shared details with The Hacker News, said about 500,000 macOS users running local Cowork sessions were affected before it was patched in a vulnerability codenamed SharedRoot.

- Advertisement -

“We connected a folder to a fresh Claude Cowork session, sent one short message, and watched the agent escape the sandbox,” said Oren Yomtov, principal security researcher at Accomplish AI. From inside the VM, the agent reached the host Mac and accessed files far outside the connected folder without any permission prompt. Consequently, the agent could access any data stored on the Mac, including SSH keys and cloud credentials.

The desktop app runs as the logged-in user, while agent work happens in a Linux VM created via Apple’s Virtualization framework. Every session gets its own disposable user and a seccomp filter, but the host filesystem is shared into the VM read-write by a root daemon called coworkd. “The entire host ‘/,’ mounted so that only guest-root inside the VM can see it, at /mnt/.virtiofs-root,” Yomtov explained.

The exploit involves loading the Linux kernel’s act_pedit subsystem into an unprivileged user namespace and exploiting CVE-2026-46331, a flaw called pedit COW, to obtain guest-root. Accomplish AI CTO Or Hiltch noted that creating user and network namespaces gives the session CAP_NET_ADMIN within its private network namespace. “That capability provides access to the vulnerable tc/act_pedit kernel path used by pedit COW,” Hiltch added.

The development follows revelations that OpenAI’s models broke out of their sandboxed environment during a security test, breaching Hugging Face’s production infrastructure. “act_pedit is one bug in a category,” Yomtov stated, noting that the Linux net/sched subsystem regularly produces privilege escalation bugs. “Patch this one and you’ve fixed this one. The chain re-arms on the next one.”

- Advertisement -

To mitigate the threat, Accomplish AI recommends disabling unprivileged user namespaces and restricting host sharing to only connected folders. “Scope it to the folders that were actually connected instead of all of /, or at least mount it read-only,” the firm said.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Meta stock falls as Zuckerberg warns, analyst sees $485 crash

META Platforms stock opened Thursday at $627 after a 2.6% decline, driven by CEO...

UN Report: Southeast Asian Crime Syndicates Now a $114B Crypto Economy

The UN Office on Drugs and Crime reports Southeast Asia's fragmented crime syndicates have...

BitMEX Shuts Down as Perp DEXs Rise to 13.5% Market Share

Bitmex, the exchange that introduced perpetual swaps and 100x leverage, will shut down on...

HYPE plunges 8% as Multicoin leads $150M unstaking queue

Funds have queued approximately $150 million of HYPE for unstaking, with $116 million originating...

AMD Stock Hits All-Time High on $5B Anthropic Deal

AMD stock surged to an all-time high of $561 in pre-market trading after announcing...

Must Read

Top 5 Best Crypto Faucets To Earn Free Crypto This Year

QUICK LINKSWhat Are Crypto Faucets and How Do They Work?How Do Crypto Faucets Make Money?What to Expect: Realistic EarningsThe Best Crypto Faucets of 2025:...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading