Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
PoC publicClaude CoworkLinux VMOur summary
Researchers discovered a sandbox escape vulnerability in Anthropic's Claude Cowork that allows an AI agent to break out of its Linux VM and access the host macOS system. The flaw, named SharedRoot, could let attackers read or write files across the user’s Mac, including sensitive data like SSH keys and cloud credentials. A proof-of-concept was demonstrated using a recently disclosed Linux kernel flaw (CVE-2026-46331) to gain elevated privileges within the VM. While Anthropic has shifted new sessions to cloud execution by default, users running Cowork locally remain at risk until additional mitigations are applied.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.