Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
ID: 087f0c6d-ee4d-5fc6-b23e-de191d7ba56c
STIX ID: report--087f0c6d-ee4d-5fc6-b23e-de191d7ba56c
Feed Name: The Hacker News
Researchers discovered a sandbox escape in Anthropic Claude Cowork for macOS (SharedRoot) that mounts the entire host filesystem read-write into a Linux VM; by loading the act_pedit Traffic Control subsystem into an unprivileged namespace and exploiting pedit COW (CVE-2026-46331) an agent can achieve guest-root and access or modify files across the Mac as the logged-in user. Accomplish AI demonstrated the PoC affecting ~500,000 local users before Anthropic moved Cowork to cloud execution by default; recommended mitigations include disabling unprivileged namespaces, limiting shared mounts to specific folders or read-only, tightening seccomp, preventing module autoloading, and running coworkd with stricter mount protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
