SharedRoot Vulnerability Allows Claude Cowork AI to Escape Sandbox on macOS

SharedRoot Vulnerability Allows Claude Cowork AI to Escape Sandbox on macOS

First seen 23 Jul 2026, 18:34 UTC ThehackernewsFeeds.4SysopsGbhackersAiweekly.Co 78% similarity 69.8

Article Content

Browse articles
ThreatCluster

A critical vulnerability, dubbed SharedRoot, has been discovered in Anthropic's Claude Cowork that permits AI agents to escape their Linux virtual machine sandbox on macOS. By exploiting CVE-2026-46331, an attacker can gain unauthorized read and write access to the host file system, potentially exposing sensitive data such as SSH keys and cloud credentials. Approximately 500,000 macOS users running local Cowork sessions are affected, as the application mounts the entire host file system into the VM with read-write privileges. Despite the severity, Anthropic has reportedly categorized the issue as 'informative' and has not issued a patch, assuming users will transition to the cloud execution model. This decision raises concerns about the security of local execution environments. Users are advised to mount folders as read-only and treat the VM's security guarantees with caution.

Key Points: • The SharedRoot vulnerability allows AI agents to escape their VM and access sensitive files. • Approximately 500,000 macOS users running local sessions are at risk due to the flaw. • Anthropic has not issued a patch, treating the local sandbox as a convenience rather than a security boundary.

ThreatCluster AI

Timeline

2026-06-16
CVE-2026-46331 published
A kernel flaw was disclosed, enabling unauthorized access to host file systems from within a VM.
Aiweekly.Co
2026-06-17
First public PoC for CVE-2026-46331
A proof of concept for the vulnerability was made publicly available, demonstrating the exploit.
Aiweekly.Co
2026-07-23
Security flaw reported in Claude Cowork
The SharedRoot vulnerability was reported, highlighting risks to sensitive data for local users.
Feeds.4Sysops
2026-07-24
Accomplish AI reports on SharedRoot escape
Accomplish AI researchers detail the exploit mechanics and the lack of a patch from Anthropic.
Aiweekly.Co

Community

Browse all →