{"id":1972,"date":"2026-07-23T14:57:57","date_gmt":"2026-07-23T14:57:57","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1972"},"modified":"2026-07-23T14:57:57","modified_gmt":"2026-07-23T14:57:57","slug":"claude-cowork-flaw-could-let-ai-agent-escape-its-vm-and-access-mac-files","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1972","title":{"rendered":"Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhj5Vr8pje9uM-Ce6rzE-_hhU3HvR2NkKtYfaSrIXz3m0BbrC1ZNC9p4GW4GRQaAvFKPjE5kopXmdmcKcMb7_1dbOWvMO6_oe87HCj4TUXV1dWK99cz_OBcNHd81Ziat93g4wJcBdc3K1vq0IkwFL9DO9GlSrf_KxGi2hpg7VVsU9iTt7B2XByXL7nil86i\/s1700-e365\/claude.gif\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic&#8217;s <a href=\"https:\/\/claude.com\/product\/cowork\" target=\"_blank\">Claude Cowork<\/a> that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.<\/p>\n<p>Accomplish AI, which shared details of the vulnerability with The Hacker News ahead of publication, said about 500,000 macOS users running local Cowork sessions were affected prior to it being patched. It has been codenamed <b>SharedRoot<\/b>.<\/p>\n<p>\u00abWe connected a folder to a fresh Claude Cowork session, sent one short message, and watched the agent escape the sandbox,\u00bb Oren Yomtov, principal security researcher at Accomplish AI, <a href=\"https:\/\/www.accomplish.ai\/blog\/sharedroot-escaping-claude-cowork-sandbox\/\" target=\"_blank\">said<\/a>. \u00abFrom inside the VM, it reached the host Mac and read and wrote files all over it, far outside the folder we&#8217;d connected, with no permission prompt anywhere.\u00bb<\/p>\n<p>With this level of access, the agent can access any data stored on the Mac via the user&#8217;s account, including SSH keys, cloud credentials, and other valuable information.<\/p>\n<p>Following responsible disclosure, Anthropic closed the report as informative without issuing a fix. That said, the latest version of Cowork defaults to cloud execution, which addresses the issue. But users who opt to run the agent locally are still exposed to the problem.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Claude Cowork&#8217;s macOS desktop app runs as the user who is logged into the system. The actual agent-related work, on the other hand, happens in a Linux VM created via Apple&#8217;s <a href=\"https:\/\/developer.apple.com\/documentation\/virtualization\" target=\"_blank\">Virtualization framework<\/a>. Every session gets its own disposable unprivileged user, along with a Secure Computing Mode (seccomp) filter for application sandboxing. The folders connected by the user are shared into the VM by a root daemon called coworkd.<\/p>\n<p>\u00abOne detail matters more than the rest: the host filesystem gets shared into that VM read-write,\u00bb Yomtov explained. \u00abThe entire host &#8216;\/,&#8217; mounted so that only guest-root inside the VM can see it, at \/mnt\/.virtiofs-root.\u00bb<\/p>\n<p>Because the entire host file system is mounted into the agent&#8217;s VM with read-write privileges, any path to guest-root can grant the agent access to the underlying host, effectively escaping the sandbox.<\/p>\n<p>This involves loading the Linux kernel&#8217;s \u00abact_pedit\u00bb Traffic Control (tc) packet editing subsystem into an unprivileged user namespace and exploiting <a href=\"https:\/\/thehackernews.com\/2026\/06\/new-linux-pedit-cow-exploit-enables.html\" target=\"_blank\">CVE-2026-46331 in the guest kernel, a recently disclosed flaw called pedit COW, to obtain guest-root. From there, the agent can access the whole host (\u00abhttps:\/\/thehackernews.com\/\u00bb) with elevated privileges, allowing it to read or write files from and to the Mac&#8217;s file system as the logged-in desktop user.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh7w4UG99yP4m-ve8gVwEPvso3_thT0vixtu6gyIUo7k1hwNr3skO_YWt594i8U3fGdq0rwe3qpTpKSrbG6K82h6BqdIDjS1brw1cXUVSnHjbSTwdlC0ZrI6nxM21V4vYMaNGPCwH9fil6tRl3xtau35z3c8PkK5BhKel44kFPjUHS0CGlj5cBfmGEg01CI\/s1700-e365\/vm.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh7w4UG99yP4m-ve8gVwEPvso3_thT0vixtu6gyIUo7k1hwNr3skO_YWt594i8U3fGdq0rwe3qpTpKSrbG6K82h6BqdIDjS1brw1cXUVSnHjbSTwdlC0ZrI6nxM21V4vYMaNGPCwH9fil6tRl3xtau35z3c8PkK5BhKel44kFPjUHS0CGlj5cBfmGEg01CI\/s1700-e365\/vm.jpg\" alt=\"\" border=\"0\" data-original-height=\"742\" data-original-width=\"1364\"\/><\/a><\/div>\n<p>Or Hiltch, co-founder and CTO of Accomplish AI, told The Hacker News that creating user and network namespaces gives the session <a href=\"https:\/\/man7.org\/linux\/man-pages\/man7\/capabilities.7.html\" target=\"_blank\">CAP_NET_ADMIN<\/a> within its private network namespace, allowing it to perform various network-related operations.<\/p>\n<p>\u00abThat capability provides access to the vulnerable tc\/act_pedit kernel path used by pedit COW,\u00bb Hiltch added. \u00abThe namespaces are not the exploit; they make its normally privileged prerequisite available to an ordinary user.\u00bb<\/p>\n<p>The development assumes significance in the face of revelations that OpenAI&#8217;s models managed to break out of its sandboxed environment during a security test that resulted in the breach of Hugging Face&#8217;s production infrastructure in their quest to cheat the ExploitGym benchmark they were being graded on.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thn.news\/sygnia-webinar\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhrEy9jEFSadp95ztaH87-97Z_U9V94nUsE-BsrdwSR8ETPJDyCjy63vNxc-O26z6VhA3nDOrU24lJqNdy24bfNxGPxGxXNRvM_XCwnZ7ukY5wDnXKsvDZN42aCT1JFYXZZGoZFEtSQgbba742oPTEgEbtoa0GBYWWkkkU43P1wPq-LByZPJfbzwZsb1RiI\/s728-e100\/sygnia-d-1.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abact_pedit is one bug in a category,\u00bb Yomtov said. \u00abThe Linux net\/sched subsystem throws off this exact shape of privilege escalation on a regular cadence: an autoloadable module, a config path an unprivileged user can reach, a memory bug at the end of it. Patch this one and you&#8217;ve fixed this one. The chain re-arms on the next one, with everything above the kernel untouched.\u00bb<\/p>\n<p>\u00abAnd the next one is always coming. At any given moment there&#8217;s likely a privilege-escalation bug it&#8217;s still exposed to, sometimes fixed upstream but not yet in your image, sometimes not yet fixed anywhere, with a working exploit out within hours. This isn&#8217;t a patch-faster problem. You&#8217;re structurally one bug behind, all the time.\u00bb<\/p>\n<p>To mitigate the threat, it&#8217;s essential to <a href=\"https:\/\/ubuntu.com\/blog\/ubuntu-23-10-restricted-unprivileged-user-namespaces\" target=\"_blank\">disable unprivileged user namespaces<\/a>, avoid making the seccomp filter overly permissive, stop autoloading of modules, and restrict sharing of the whole host into the VM.<\/p>\n<p>\u00abScope it to the folders that were actually connected instead of all of \/, or at least mount it read-only, and run coworkd with ProtectSystem=strict in its own mount namespace so it isn&#8217;t re-execing binaries a session user can poison,\u00bb Accomplish said. \u00abThen even a full guest-root has nothing to land on, the last two steps of the chain have nowhere to go.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic&#8217;s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1973,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[130,683,9,2687,1349,236,70,2321],"class_list":["post-1972","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-access","tag-agent","tag-claude","tag-cowork","tag-escape","tag-files","tag-flaw","tag-mac"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1972","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1972"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1972\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1973"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1972"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1972"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1972"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}