Skip to content
Security flaw in Claude Cowork allows AI agent to escape sandbox on macOS

Security flaw in Claude Cowork allows AI agent to escape sandbox on macOS

Feeds.4Sysops IT News July 23, 2026

A critical vulnerability known as SharedRoot allows AI agents within Anthropic’s Claude Cowork to break out of their Linux virtual machine sandbox on macOS. By exploiting a kernel flaw, an agent can gain unauthorized read and write access to the host file system, potentially exposing sensitive data like SSH keys and cloud credentials. This issue affects approximately 500,000 users who run the agent locally, as the application mounts the entire host file system into the virtual machine with read-write privileges. Source

Extracted Entities