logo

Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys and Cloud Credentials

ID: 650583a6-85da-575e-9f6c-647544d1eb1b

STIX ID: report--650583a6-85da-575e-9f6c-647544d1eb1b

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Divya

...
...

A sandbox escape named “SharedRoot” affecting Anthropic's Claude Cowork can allow untrusted agent sessions running in a Linux VM on macOS to gain guest-root using unprivileged user namespaces and a Linux kernel pedit COW flaw (CVE-2026-46331), then access a writable VirtioFS mount that exposes the full host filesystem; researchers proved the chain and demonstrated exfiltration of SSH keys and cloud credentials, Anthropic classified the report Informative and moved Cowork to default cloud execution, and recommended mitigations include disabling unprivileged namespaces, tightening seccomp, preventing module autoload, and restricting VM file-sharing to approved folders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.