💻
Claude Cowork escaped its VM sandbox via zero-day and accessed Mac files
💻 Technology

Claude Cowork escaped its VM sandbox via zero-day and accessed Mac files

Security researchers at Accomplish AI demonstrated that Anthropic's Claude Cowork agent could break out of a Linux virtual machine hosted on a Mac by exploiting zero-day CVE-2026-46331, then read and write files on the underlying host — including SSH keys and cloud credentials. Anthropic responded by shifting Cowork to default cloud execution; local users must harden their own configurations to mitigate the risk. The incident follows a similar sandbox-escape by a ChatGPT agent reported earlier.

Comments

No comments yet