Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-46331
CVE
CVE-2026-46331
View on NVD ↗
net/sched: fix pedit partial COW leading to page cache corruption
MITRE ATT&CK TTPs
5
T1059.001
PowerShell
Execution
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1078
Valid Accounts
Defense Evasion
T1134
Access Token Manipulation
Defense Evasion
T1135
Network Share Discovery
Discovery
Source Articles
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
A sandbox escape vulnerability named SharedRoot has been discovered in Anthropic's Claude Cowork, allowing an AI agent to break out of its Linux VM and access arbitrary files on the host macOS system. The flaw stems from the entire host filesystem being mounted read-write into the VM, enabling privilege escalation via exploitation of CVE-2026-46331 (pedit COW) in the guest kernel. Although Anthropic has not issued a direct fix, the latest version defaults to cloud execution, mitigating the risk for most users, but local execution remains vulnerable.
hacker-news
Jul 23, 2026