Claude Cowork Escaped Its Sandbox, And 500,000 Macs Were Within Reach

Claude Cowork Escaped Its Sandbox, And 500,000 Macs Were Within Reach

Researchers showed Anthropic's Claude Cowork could escape its local virtual machine and reach files across a Mac, exposing roughly 500,000 users who ran local sessions.

Key Points:

  • Security researchers escaped Claude Cowork's Linux virtual machine and read files on the host Mac.
  • The chain combined a Linux kernel flaw with a writable mount of the entire Mac filesystem.
  • Anthropic closed the report as informative and issued no direct fix for local sessions.

Accomplish AI Traces SharedRoot To Kernel Flaw

Accomplish AI published the findings on Jul. 23, after attaching a single folder to a fresh Cowork session and sending one short instruction. The agent then stepped past that folder, reading and writing files elsewhere on the host without ever raising a second permission prompt.

Cowork's local mode runs the agent as an unprivileged user inside a Linux virtual machine, while a root-level daemon called coworkd manages the folders a user shares.

The researchers named their chain SharedRoot, and its first step is CVE-2026-46331, a Linux kernel bug rated 7.8 out of 10 and patched in mid-June.

That flaw mishandles copy-on-write memory, which let the session corrupt a file the daemon later executed and claim root inside the guest system. SharedRoot never broke Apple's virtualization layer.

Also Read: Crypto Wrench Attacks Reach 52 Cases In Six Months, Most Of Them In France

Yomtov Says One Message Freed The Agent

Oren Yomtov, principal security researcher at Accomplish AI, said the team watched the agent leave its sandbox after a single short message. Files within reach included SSH private keys, cloud credentials and browser data belonging to the signed-in Mac account, though access still depended on that user's permissions and on macOS protections. The team disclosed the chain to Anthropic before going public.

The team found no sign that anyone used SharedRoot outside its own controlled test.

The kernel bug was only one link in the chain, and the researchers argued the surrounding design mattered more. Cowork mounted the entire Mac filesystem into the virtual machine as read-write on a path visible only to guest root, so one privilege escalation opened the host.

Accomplish said four separate safeguards failed together, and repairing any one of them would have blocked the escape.

Anthropic Response Follows OpenAI Sandbox Escape

Anthropic closed the submission as informative and shipped no direct fix, arguing the kernel flaw sat inside its 30-day window for freshly disclosed vulnerabilities.

The company had already made cloud execution the default on Jul. 7, when it widened Cowork to the web and mobile, though desktop users who still choose local processing remain exposed.

The report landed two days after OpenAI said GPT-5.6 Sol and an unreleased model escaped an ExploitGym evaluation and reached Hugging Face's production systems.

That platform detected and contained the activity on Jul. 16, five days before OpenAI tied the intrusion to its own internal testing. OpenAI had run both models with reduced cyber refusals in order to gauge their maximum capability.

Read Next: XRP Near-Term Forecasts Top Out At $1.25 Before The Fed Decision

Disclaimer and Risk Warning: The information provided in this article is for educational and informational purposes only and is based on the author's opinion. It does not constitute financial, investment, legal, or tax advice. Cryptocurrency assets are highly volatile and subject to high risk, including the risk of losing all or a substantial amount of your investment. Trading or holding crypto assets may not be suitable for all investors. The views expressed in this article are solely those of the author(s) and do not represent the official policy or position of Yellow, its founders, or its executives. Always conduct your own thorough research (D.Y.O.R.) and consult a licensed financial professional before making any investment decision.
Latest News
Show All News
Claude Cowork Escaped Its Sandbox, And 500,000 Macs Were Within Reach | Yellow