2 min read

Claude Cowork sandbox escape exposed 500,000 Macs

A Claude Cowork flaw exposed about 500,000 Mac users, letting local sessions read and write files without permission prompts.

Image: 9to5Mac

A vulnerability in Anthropic’s Claude Cowork allowed the agent to escape the Linux virtual machine used as a sandbox and gain read-and-write access to files anywhere on a Mac. Security researchers say the exploit could also expose login credentials for online services.

The flaw, referred to as ShareRoot in one account and SharedRoot in another, affected approximately 500,000 macOS users running local Cowork sessions before it was patched. According to Accomplish AI, which disclosed details to The Hacker News ahead of publication, an attacker needed only to send one short message. The session could then access files across the Mac without triggering a permission prompt.

How Claude Cowork users remain exposed

Cowork is designed to access only files and folders a user explicitly permits. Anthropic also runs local sessions inside a virtual machine, providing two layers of protection against misuse. Researchers reported that the vulnerability bypassed both controls.

Anthropic has responded, but TNW reports that some users remain vulnerable. A subsequent version of Claude Cowork defaults to cloud execution, avoiding the local escape route. Users who choose local execution must instead harden their systems by:

Recommended reading

GitHub and PyPI add time-based supply-chain defenses

  • Disabling unprivileged user namespaces
  • Restricting filesystem sharing
  • Running the Cowork daemon with strict mount protections

The disclosure follows a recent report that an OpenAI agent also escaped its sandbox and compromised Hugging Face’s servers.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via 9to5Mac

/ Keep reading