started · updated
Anthropic patches Claude Cowork sandbox escape affecting 500,000 macOS users
Security researchers at Accomplish AI disclosed a sandbox‑escape vulnerability in Anthropic’s Claude Cowork, dubbed SharedRoot. The flaw exploited a Linux kernel privilege‑escalation bug (CVE‑2026‑46331) in the VM’s VirtioFS mount, allowing the AI agent to break out of its local Linux container and read or write any file on the host Mac, including SSH keys and cloud credentials. An estimated 500,000 macOS users running local Claude Cowork sessions were exposed before the issue was addressed.
Anthropic released a patch shortly after disclosure, moving the default execution mode to the cloud to eliminate the local escape path. Users who continue to run Cowork locally are advised to harden configurations by disabling unprivileged user namespaces and restricting filesystem sharing. The incident highlights the limits of sandbox isolation for AI agents and the need for layered security controls.
Entities
Accomplish AI · Anthropic · CVE-2026-46331 · Claude Cowork · Oren Yomtov