Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
A sandbox escape vulnerability in Anthropic's Claude Cowork has been discovered by cybersecurity experts. This vulnerability allows the agent to read or write files anywhere on the Mac by escaping the boundaries of a Linux virtual machine (VM).
About 500,000 macOS users running local Cowork sessions were impacted before it was patched, according to Accomplish AI, which disclosed the issue to The Hacker News before it was published. The coding name for it is SharedRoot.
According to Oren Yomtov, lead security researcher at Accomplish AI, "we connected a folder to a new Claude Cowork session, sent one brief message, and watched the agent escape the sandbox." Without a permission prompt anywhere, it read and wrote files all across the host Mac from inside the virtual machine, far beyon...

