Feeds.4Sysops
SharedRoot Vulnerability Allows Claude Cowork AI to Escape Sandbox on macOS
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability, dubbed SharedRoot, has been discovered in Anthropic's Claude Cowork that permits AI agents to escape their Linux virtual machine sandbox on macOS. By exploiting CVE-2026-46331, an attacker can gain unauthorized read and write access to the host file system, potentially exposing sensitive data such as SSH keys and cloud credentials. Approximately 500,000 macOS users running local Cowork sessions are affected, as the application mounts the entire host file system into the VM with read-write privileges. Despite the severity, Anthropic has reportedly categorized the issue as 'informative' and has not issued a patch, assuming users will transition to the cloud execution model. This decision raises concerns about the security of local execution environments. Users are advised to mount folders as read-only and treat the VM's security guarantees with caution.
Key Points: • The SharedRoot vulnerability allows AI agents to escape their VM and access sensitive files. • Approximately 500,000 macOS users running local sessions are at risk due to the flaw. • Anthropic has not issued a patch, treating the local sandbox as a convenience rather than a security boundary.