logo

SharedRoot: Sandbox Escape in Claude Cowork

ID: e11cb684-6d54-596f-9d87-fa8fb74655f7

STIX ID: report--e11cb684-6d54-596f-9d87-fa8fb74655f7

Feed Name: SOCRadar Blog

Threat Score
55/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

Author: ameer

...
...

SharedRoot is an attack chain that combines CVE-2026-46331 (a Linux act_pedit traffic-control flaw) with Claude Cowork’s local macOS VM and its host-filesystem sharing to achieve sandbox escape, potentially exposing or modifying files accessible to the logged-in macOS user; researchers demonstrated a PoC on macOS but there is no confirmed in-the-wild exploitation. The report details affected components, exploitability conditions, detection guidance, and mitigations (patch guest kernels, prefer cloud Cowork mode, restrict namespaces/netlink, and narrow host mounts).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.