It's not just OpenAI models escaping and running riot — experts show how Claude Cowork can break its bonds…

https://cdn.mos.cms.futurecdn.net/kQgz8fSBJp3j2YakUJFn4N-2560-80.jpg
  • Accomplish AI showed Claude Cowork could escape a VM sandbox via Linux zero‑day CVE‑2026‑46331
  • Agent accessed host Mac files, risking exfiltration of SSH keys, cloud credentials, and more
  • Anthropic shifted Cowork to default cloud execution; local users must harden configs to mitigate exposure

Recent news of a ChatGPT agent escaping the sandbox and attacking services on the internet raised quite a few eyebrows, but it seems it’s not the only one capable of running wild. Security researchers Accomplish AI are saying they achieved similar results with Anthropic’s Claude Cowork.

In a new report, the researchers said they ran a local session in a Mac-hosted virtual Linux machine and then observed as the agent broke free of the VM and started reading and writing files on the underlying system.

“We connected a folder to a fresh Claude Cowork session, sent one short message, and watched the agent escape the sandbox,” Oren...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more