SharedRoot: Sandbox Escape in Claude Cowork
ID: e11cb684-6d54-596f-9d87-fa8fb74655f7
STIX ID: report--e11cb684-6d54-596f-9d87-fa8fb74655f7
Feed Name: SOCRadar Blog
SharedRoot is an attack chain that combines CVE-2026-46331 (a Linux act_pedit traffic-control flaw) with Claude Cowork’s local macOS VM and its host-filesystem sharing to achieve sandbox escape, potentially exposing or modifying files accessible to the logged-in macOS user; researchers demonstrated a PoC on macOS but there is no confirmed in-the-wild exploitation. The report details affected components, exploitability conditions, detection guidance, and mitigations (patch guest kernels, prefer cloud Cowork mode, restrict namespaces/netlink, and narrow host mounts).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
