Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Summary
Researchers discovered a sandbox escape vulnerability in Anthropic's Claude Cowork that allows an AI agent running in a Linux VM (virtual machine, an isolated computing environment) to break out and access files anywhere on a Mac computer. The flaw, called SharedRoot, affected about 500,000 macOS users and works because the entire Mac file system is mounted into the agent's VM with read-write access, allowing the agent to exploit a Linux kernel bug to gain elevated privileges and steal sensitive data like SSH keys and passwords.
Solution / Mitigation
The latest version of Cowork defaults to cloud execution, which addresses the issue. However, users who opt to run the agent locally remain exposed to the problem.
Classification
Affected Vendors
Related Issues
Original source: https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html
First tracked: July 23, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%