S&P 5007,413.18▲0.0% Nasdaq24,932.08▼0.2% Dow52,210.08▲0.5% Russell 2K2,948.03▲0.6% 10-Yr4.64%−4bp VIX18.67+0.09 WTI$81.92▼8.3% Gold$4,078.90▲0.3% EUR/USD1.137▼0.0% BTC$63,684▼0.1% Nikkei64,611▼2.7%
At close · Mon, Jul 27, 2026
Daily Market Updates.

Crypto

HomeCryptoMarket StructureResearchers say Claude Cowork can escape its local san…

Researchers say Claude Cowork can escape its local sandbox on macOS

The analysis found the agent could read and write host files, including SSH keys and cloud credentials, affecting an estimated 500,000 macOS users before a fix.

Security researchers at Accomplish AI say Anthropic’s Claude Cowork can escape its local virtual machine in a macOS setup, allowing the agent to access files on the host computer, according to Decrypt. The report describes a “local execution mode” that can break out of a Linux VM by chaining architectural weaknesses with a Linux kernel privilege escalation flaw. Once outside the sandbox, Cowork could read and write files wherever the logged-in Mac user has access, including SSH keys and cloud credentials.

Decrypt said Accomplish AI argues the kernel bug alone was not enough, and that the escape worked because multiple safeguards failed at the same time. The researchers say the VM had access to the host computer’s entire filesystem and could load kernel modules it did not need, and that fixing any one weakness would have stopped the attack.

In response, Accomplish AI said roughly 500,000 macOS users running local Claude Cowork sessions were affected before the issue was addressed. Decrypt added that Anthropic classified the findings as “informative,” citing its 30 day window for recently disclosed vulnerabilities and framing remaining items as defense in depth recommendations.

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.