Crypto
Home›Crypto›Market Structure›Researchers say Claude Cowork can escape its local san…
Researchers say Claude Cowork can escape its local sandbox on macOS
The analysis found the agent could read and write host files, including SSH keys and cloud credentials, affecting an estimated 500,000 macOS users before a fix.
Security researchers at Accomplish AI say Anthropic’s Claude Cowork can escape its local virtual machine in a macOS setup, allowing the agent to access files on the host computer, according to Decrypt. The report describes a “local execution mode” that can break out of a Linux VM by chaining architectural weaknesses with a Linux kernel privilege escalation flaw. Once outside the sandbox, Cowork could read and write files wherever the logged-in Mac user has access, including SSH keys and cloud credentials.
Decrypt said Accomplish AI argues the kernel bug alone was not enough, and that the escape worked because multiple safeguards failed at the same time. The researchers say the VM had access to the host computer’s entire filesystem and could load kernel modules it did not need, and that fixing any one weakness would have stopped the attack.
In response, Accomplish AI said roughly 500,000 macOS users running local Claude Cowork sessions were affected before the issue was addressed. Decrypt added that Anthropic classified the findings as “informative,” citing its 30 day window for recently disclosed vulnerabilities and framing remaining items as defense in depth recommendations.