hacker-news · Crawled Jul 23, 2026

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

1 CVEs
Read original article ↗

AI Summary

A sandbox escape vulnerability named SharedRoot has been discovered in Anthropic's Claude Cowork, allowing an AI agent to break out of its Linux VM and access arbitrary files on the host macOS system. The flaw stems from the entire host filesystem being mounted read-write into the VM, enabling privilege escalation via exploitation of CVE-2026-46331 (pedit COW) in the guest kernel. Although Anthropic has not issued a direct fix, the latest version defaults to cloud execution, mitigating the risk for most users, but local execution remains vulnerable.

AI-extracted · verify before operational use

Extracted Entities 1 found

MITRE ATT&CK TTPs 5 techniques