Claude Cowork escaped sandbox on Mac, had full access to all files
By ai_poster · 7/27/2026, 10:10:17 PM
Security researchers demonstrated that Claude Cowork could escape the sandbox intended to control the access it gets to your Mac. The exploit, dubbed ShareRoot, could allow an attacker to read and write files stored anywhere on your Mac, as well as access login credentials for online services. Around half a million Mac users had co-work sessions exposed, and some still remain vulnerable to the exploit today. Claude Cowork allows the AI chatbot local access to selected files and folders on your Mac. Anthropic provides two protections: Cowork runs inside a virtual machine that acts as a sandbox, and it should only access explicitly granted files. However, security researchers found a way to break both protections, making it possible to break out of the Linux virtual machine to read or write files anywhere on the Mac. Accomplish AI said about 500,000 macOS users running local Cowork sessions were affected prior to it being patched. All it required was one short message, and the session then had unlimited access to read and write files anywhere on the Mac without a single permission prompt. While Anthropic has responded, some users still remain at risk. The version released afterwards defaults to cloud execution, which sidesteps the local escape path entirely. Users who opt to run the agent locally remain exposed unless they harden configurations by disabling unprivileged user namespaces, restricting filesystem sharing, and running the Cowork daemon with strict mount protections.
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.