Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys and Cloud Credentials
ID: 650583a6-85da-575e-9f6c-647544d1eb1b
STIX ID: report--650583a6-85da-575e-9f6c-647544d1eb1b
Feed Name: GBHackers
A sandbox escape named “SharedRoot” affecting Anthropic's Claude Cowork can allow untrusted agent sessions running in a Linux VM on macOS to gain guest-root using unprivileged user namespaces and a Linux kernel pedit COW flaw (CVE-2026-46331), then access a writable VirtioFS mount that exposes the full host filesystem; researchers proved the chain and demonstrated exfiltration of SSH keys and cloud credentials, Anthropic classified the report Informative and moved Cowork to default cloud execution, and recommended mitigations include disabling unprivileged namespaces, tightening seccomp, preventing module autoload, and restricting VM file-sharing to approved folders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
