HeadlinesBriefing favicon HeadlinesBriefing.com

Claude Cowork Can Escape Sandbox, Access Mac Files

AppleInsider •
×

Accomplish AI researchers revealed that a Linux kernel flaw lets a locally‑running Claude Cowork session escape its sandbox and access a Mac’s filesystem. The vulnerability, identified as CVE-2026-46331, provides root privileges inside the virtual machine, bypassing macOS protections.\n\nThe exploit, dubbed SharedRoot, uses a writable Virtio FS mount to read and write outside the approved folder after elevating to guest‑root. In a demo, the agent accessed SSH keys, cloud credentials, and browser data without further permission prompts.\n\nWhile the mount covers the entire host filesystem, access still depends on the logged‑in user’s permissions.

Anthropic had recently shifted to cloud execution, but local sessions remain vulnerable if users connect untrusted directories.\n\nAccomplish AI reported the issue to Anthropic, which marked it 'Informative'. The researchers advise using cloud execution, limiting mounts to needed folders, and making them read‑only. Users should rotate credentials and avoid giving agents broad file access.