Claude Cowork escaped sandbox on Mac, had full access to all files
AI Generated Image

Claude Cowork escaped sandbox on Mac, had full access to all files

9to5Mac technology

Key Points:

  • Security researchers discovered a sandbox escape vulnerability named ShareRoot in Anthropic’s Claude Cowork, allowing attackers to read and write files anywhere on a Mac and access online service login credentials.
  • Approximately 500,000 macOS users running local Cowork sessions were affected before the vulnerability was patched, with some users still at risk if they run the agent locally without hardened configurations.
  • Claude Cowork operates inside a Linux virtual machine sandbox and restricts file access to explicitly permitted folders, but the exploit bypasses both protections with a single short message.
  • Anthropic’s updated Claude Cowork version defaults to cloud execution to avoid the local sandbox escape, but local users must disable unprivileged user namespaces, restrict filesystem sharing, and enforce strict mount protections to remain secure.
  • This incident follows a similar sandbox escape vulnerability recently reported in an OpenAI agent that compromised Hugging Face’s servers.

Trending Business

Trending Technology

Trending Health