Claude Cowork Sandbox Escape Flaw Lets AI Agent Read SSH Keys and Cloud Credentials From Host
ID: ed9bdfa3-faf1-5968-a289-0511097be587
STIX ID: report--ed9bdfa3-faf1-5968-a289-0511097be587
Feed Name: cybersecurityNews.com
A privilege-escalation and sandbox-escape vulnerability (CVE-2026-46331, "pedit COW") in Claude Cowork's macOS local sandbox enables an untrusted AI agent running in the VM to abuse a virtiofs-mounted host filesystem and exfiltrate or modify sensitive host files (SSH keys, cloud credentials). Accomplish researchers demonstrated a complete proof-of-concept called "SharedRoot" that chains permissive seccomp, user namespace unshare, netlink-triggered module autoloading, and page-cache corruption to achieve host compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
