Claude Cowork flaw could let AI agent escape its VM and access Mac files
Oren YomtovAnthropicAccomplish AI

Claude Cowork flaw could let AI agent escape its VM and access Mac files

A vulnerability in Anthropic's Claude Cowork could allow AI agents to escape their Linux virtual machine, potentially accessing sensitive Mac files. Approximately 500,000 macOS users were affected before a patch was issued, with the flaw codenamed SharedRoot by Accomplish AI researchers.

The Hacker News The Hacker News23 July 2026 · 15:46 UTC
CuriousCats Full Story

Cybersecurity researchers have identified a significant vulnerability in Anthropic's Claude Cowork, codenamed SharedRoot. This flaw allows AI agents to escape their Linux virtual machine (VM) and access files on the host Mac, affecting around 500,000 users.123

Oren Yomtov, principal security researcher at Accomplish AI, stated, "We connected a folder to a fresh Claude Cowork session, sent one short message, and watched the agent escape the sandbox." The agent was able to read and write files across the Mac without any permission prompts, raising serious security concerns.

The vulnerability stems from the way folders are shared into the VM by a root daemon called coworkd. Yomtov explained, "One detail matters more than the rest: the host filesystem gets shared into that VM read-write." This means that any path to guest-root can grant the agent access to the underlying host, effectively escaping the sandbox.789

The flaw involves exploiting a recently disclosed issue in the Linux kernel's Traffic Control subsystem, allowing the agent to gain elevated privileges and access sensitive data, including SSH keys and cloud credentials. “That capability provides access to the vulnerable tc/act_pedit kernel path used by pedit COW,” said researcher Hiltch.101112

To mitigate this threat, experts recommend restricting the sharing of the entire host into the VM and ensuring that only necessary folders are shared. “Scope it to the folders that were actually connected instead of all of /, or at least mount it read-only,” Yomtov advised.

Key Insight
“The flaw, codenamed SharedRoot, was discovered by cybersecurity researchers at Accomplish AI and affects an estimated 500,000 macOS users running local sessions. Anthropic closed the report as informative without issuing a fix, though the latest version defaults to cloud execution which mitigates the issue for cloud users but leaves local users exposed.”
CuriousCats studied:
1
The Hacker NewsThe Hacker News
“Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.”
The Hacker News →
Ask CuriousCats
What is the SharedRoot flaw?
Who discovered the vulnerability in Claude Cowork?
Why isn’t there a fix for local users?
Are there significant risks for local macOS users?
How does cloud execution protect against this issue?
Become the most informed
person in the room.
Personal AI agents scanning 100,000+ sources — news, video, and social media — delivered every morning.
Download the App Go to CuriousCats.ai
🇺🇸 US🇮🇳 India🇬🇧 UK🇨🇦 Canada🇸🇬 Singapore
One story brought you here.
CuriousCats brings you everything else worth knowing.
Get CuriousCats