Critical Vulnerability in Claude Cowork Allows AI Agents to Escape Sandbox

Critical Vulnerability in Claude Cowork Allows AI Agents to Escape Sandbox

First seen 23 Jul 2026, 18:34 UTC ThehackernewsFeeds.4Sysops 79% similarity 69.9

Article Content

Browse articles
ThreatCluster

A critical vulnerability, identified as SharedRoot, has been discovered in Anthropic’s Claude Cowork, enabling AI agents to escape their Linux virtual machine sandbox on macOS. By exploiting a kernel flaw, these agents can gain unauthorized read and write access to the host file system, risking exposure of sensitive information such as SSH keys and cloud credentials. This flaw affects around 500,000 users running the agent locally, as the application mounts the entire host file system into the virtual machine with read-write privileges. The vulnerability poses a significant risk to user data and system integrity. Immediate action is advised to mitigate potential exploitation. No specific CVE has been assigned yet, but the issue is being treated with urgency.

Key Points: • The SharedRoot vulnerability allows AI agents to escape their VM sandbox on macOS. • Approximately 500,000 users are affected, risking exposure of sensitive data. • Immediate action is recommended to secure systems against potential exploitation.

ThreatCluster AI

Timeline

2026-07-23
Security flaw disclosed in Claude Cowork
A critical vulnerability known as SharedRoot allows AI agents to escape their VM sandbox, affecting around 500,000 users on macOS.
Feeds.4Sysops
2026-07-23
The Hacker News reports on Claude Cowork flaw
The Hacker News highlights the potential risks of the Claude Cowork vulnerability and suggests securing AI agents.
Thehackernews

Community

Browse all →