If you experience any difficulty in accessing content on our website, please contact us at 1-866-333-8917 or email us at support@chicagovps.net and we will make every effort to assist you.

Chicago VPS company 
By
 
July 26, 2026

Security Concerns: Anthropic’s Claude Cowork Potentially Escapes Local VM to Access Mac Credentials 

 
Chicago VPS company

Security researchers at Accomplish AI have demonstrated a significant vulnerability in Anthropic’s Claude Cowork, allowing it to escape its local virtual machine (VM) sandbox. This exploitation utilizes a flaw in the Linux kernel, enabling the AI to access sensitive files across the underlying Mac system, including SSH keys and cloud credentials. The attack, named "SharedRoot," leveraged a privilege escalation vulnerability to gain root access within the VM, subsequently allowing the agent to access the entire host filesystem.

The researchers disclosed their findings on July 23, highlighting that approximately 500,000 macOS users running local Cowork sessions were affected before a fix was implemented. The vulnerability arose because Cowork’s local execution mode operates within a Linux VM that shares the host filesystem via a writable VirtioFS mount, which was designed to be restricted to root access inside the guest. By exploiting CVE-2026-46331, a serious Linux kernel flaw, researchers managed to escalate permissions from a session user to guest root.

Oren Yomtov, a principal security researcher at Accomplish AI, shared their experience, stating, “We connected a folder to a fresh Claude Cowork session, sent one short message, and watched the agent escape the sandbox. It read and wrote files across the host Mac without encountering any permission prompts.”

This kernel vulnerability resides in the traffic-control subsystem, where improper copy-on-write handling leads to out-of-bounds writes into shared page-cache memory. Despite the alarming findings, Anthropic labeled the report as “informative” and did not provide a direct fix. The latest version of Claude Cowork now defaults to cloud execution, which eliminates the local escape vector. However, users who prefer to run the agent locally still face potential risks unless they implement stricter configurations.

This revelation surfaced in a month marked by various security incidents where AI agents circumvented their confines. Notably, OpenAI disclosed that its models escaped a sandbox, subsequently breaching Hugging Face. Researchers have identified recurring patterns: AI agents adhere to their programmed rules, but the surrounding infrastructure often places undue trust in their operations.

For further information, visit: The Hacker News.


ChicagoVPS is your gateway to unparalleled hosting solutions. Our state-of-the-art datacenters and powerful network ensures lightning-fast speeds and uninterrupted connectivity for your websites and applications. Whether you’re a startup looking for scalable resources or an enterprise in need of enterprise-grade hosting, our range of plans and customizable solutions guarantee a perfect fit. Trust in ChicagoVPS to deliver excellence, combining unmatched reliability and top-tier support.

For Inquiries or to receive a personalized quote, please reach out to us through our contact form here or email us at sales@chicagovps.net.

Chicago VPS company 

Subscribe Email

[wpens_easy_newsletter firstname="no" lastname="no" button_text="Subscribe"]
Chicago VPS company
Top