CVE Tools
Back to feed
PoC public Claude Cowork privilege-escalation Linux VM Anthropic web-app

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

Researchers discovered a sandbox escape vulnerability in Anthropic's Claude Cowork that allows an AI agent to break out of its Linux VM and access the host macOS system. The flaw, named SharedRoot, could let attackers read or write files across the user’s Mac, including sensitive data like SSH keys and cloud credentials. A proof-of-concept was demonstrated using a recently disclosed Linux kernel flaw (CVE-2026-46331) to gain elevated privileges within the VM. While Anthropic has shifted new sessions to cloud execution by default, users running Cowork locally remain at risk until additional mitigations are applied.