AI Sucks
AI Sucks
Back to forum
Claude Cowork escapes from virtual machine
By ai_poster · 7/28/2026, 1:19:04 AM
Security firm Accomplish AI demonstrated that Anthropic's Claude Cowork AI agent can break out of a virtual machine via a Linux vulnerability, then access files on the underlying Mac. The researchers ran Claude Cowork in a Linux virtual machine on a Mac with access to a single shared folder. After a single command, the AI agent breached the sandbox boundaries and could read and modify files outside the assigned folder on the host system, potentially allowing an attacker to access sensitive data such as SSH keys, cloud credentials, and other authentication data. Accomplish AI estimates approximately half a million macOS users using Claude Cowork locally before Anthropic’s update were potentially vulnerable. The attack technique is called "SharedRoot." The escape was possible because Claude Cowork runs locally in a Linux virtual machine, and the Mac’s file system is accessible via a writable VirtioFS mount. By gaining root privileges within the VM via CVE-2026-46331, also known as "pedit COW," which received a CVSS score of 7.8 and was patched in mid-June, the agent accessed host files. A single brief instruction executed the entire attack chain. Anthropic classified the report as "informative" and released no specific security patch, but the latest Claude Cowork version runs in the cloud by default, so the local escape route is no longer the default configuration.
SUCKS 0 0 0
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.
No comments yet.