Anthropic’s Claude Cowork could escape its local VM and read credentials on a Mac

https://media.thenextweb.com/2026/07/claude-cowork-sandbox-escape-mac-files-sharedroot.avif

TL;DR

Researchers showed Claude Cowork could escape its local VM sandbox via a Linux kernel flaw and read files across the host Mac

Security researchers at Accomplish AI demonstrated that Anthropic’s Claude Cowork could break out of its local virtual machine sandbox and read files across the underlying Mac, including SSH keys and cloud credentials. The attack, dubbed SharedRoot, exploited a Linux kernel privilege escalation vulnerability to gain root access inside the guest VM, then walked out through a writable filesystem mount that exposed the entire host. Accomplish AI disclosed the findings on July 23 and said roughly 500,000 macOS users running local Cowork sessions were exposed before the issue was addressed.

The escape chain worked because Cowork’s local execution mode runs inside a Linux VM that shares the host filesystem via a writable VirtioFS mount. That mount was intended to be accessible only to root within the guest, but...

Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE

Read more