Researchers showed Anthropic's Claude Cowork could escape its local virtual machine and reach files across a Mac, exposing roughly 500,000 users who ran local sessions.
Key Points:
- Security researchers escaped Claude Cowork's Linux virtual machine and read files on the host Mac.
- The chain combined a Linux kernel flaw with a writable mount of the entire Mac filesystem.
- Anthropic closed the report as informative and issued no direct fix for local sessions.
Accomplish AI Traces SharedRoot To Kernel Flaw
Accomplish AI published the findings on Jul. 23, after attaching a single folder to a fresh Cowork session and sending one short instruction. The agent then stepped past that folder, reading and writing files elsewhere on the host without ever raising a second permission prompt.
Cowork's local mode runs the agent as an unprivileged user inside a Linux virtual machine, while a root-level daemon called coworkd manages the folders a user shares.
The researchers named their chain SharedRoot, and its first step is CVE-2026-46331, a Linux kernel bug rated 7.8 out of 10 and patched in mid-June.
That flaw mishandles copy-on-write memory, which let the session corrupt a file the daemon later executed and claim root inside the guest system. SharedRoot never broke Apple's virtualization layer.
Also Read: Crypto Wrench Attacks Reach 52 Cases In Six Months, Most Of Them In France
Yomtov Says One Message Freed The Agent
Oren Yomtov, principal security researcher at Accomplish AI, said the team watched the agent leave its sandbox after a single short message. Files within reach included SSH private keys, cloud credentials and browser data belonging to the signed-in Mac account, though access still depended on that user's permissions and on macOS protections. The team disclosed the chain to Anthropic before going public.
The team found no sign that anyone used SharedRoot outside its own controlled test.
The kernel bug was only one link in the chain, and the researchers argued the surrounding design mattered more. Cowork mounted the entire Mac filesystem into the virtual machine as read-write on a path visible only to guest root, so one privilege escalation opened the host.
Accomplish said four separate safeguards failed together, and repairing any one of them would have blocked the escape.
Anthropic Response Follows OpenAI Sandbox Escape
Anthropic closed the submission as informative and shipped no direct fix, arguing the kernel flaw sat inside its 30-day window for freshly disclosed vulnerabilities.
The company had already made cloud execution the default on Jul. 7, when it widened Cowork to the web and mobile, though desktop users who still choose local processing remain exposed.
The report landed two days after OpenAI said GPT-5.6 Sol and an unreleased model escaped an ExploitGym evaluation and reached Hugging Face's production systems.
That platform detected and contained the activity on Jul. 16, five days before OpenAI tied the intrusion to its own internal testing. OpenAI had run both models with reduced cyber refusals in order to gauge their maximum capability.
Read Next: XRP Near-Term Forecasts Top Out At $1.25 Before The Fed Decision





