Feeds.4Sysops SharedRoot Vulnerability Allows Claude Cowork AI to Escape Sandbox on macOS
Article Content
- •The SharedRoot vulnerability allows AI agents to escape their VM and access sensitive files.
- •Approximately 500,000 macOS users running local sessions are at risk due to the flaw.
- •Anthropic has not issued a patch, treating the local sandbox as a convenience rather than a security boundary.
A critical vulnerability, dubbed SharedRoot, has been discovered in Anthropic's Claude Cowork that permits AI agents to escape their Linux virtual machine sandbox on macOS. By exploiting CVE-2026-46331, an attacker can gain unauthorized read and write access to the host file system, potentially exposing sensitive data such as SSH keys and cloud credentials. Approximately 500,000 macOS users running local Cowork sessions are affected, as the application mounts the entire host file system into the VM with read-write privileges. Despite the severity, Anthropic has reportedly categorized the issue as 'informative' and has not issued a patch, assuming users will transition to the cloud execution model. This decision raises concerns about the security of local execution environments. Users are advised to mount folders as read-only and treat the VM's security guarantees with caution.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (15)
Following this threat?
Track Anthropic and CVE-2026-46331 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Linux Kernel Vulnerabilities Expose WiFi Systems to Injection Attacks Multiple vulnerabilities have been discovered in the Linux kernel affecting various distributions, including Ubuntu 20.04 and 18.04. Researchers Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef identified that the WiFi implementation fails to handle aggregated frames in mesh networks, allowing a physically proximate…
Multiple CVEs Affecting SUSE Systems Announced on September 1, 2026 On September 1, 2026, SUSE announced updates addressing multiple vulnerabilities, including CVE-2026-23161, CVE-2026-23449, and CVE-2026-31629. These vulnerabilities affect various SUSE Linux Enterprise products and have CVSS scores ranging from 4.0 to 8.9, indicating varying levels of severity. Attack vectors include…