Inboxsmith

AI news videos

Claude Cowork flaw let its AI agent escape onto your Mac

A security firm found a sandbox escape flaw in Claude Cowork, Anthropic's Mac app, that let its AI agent break out of its Linux VM and read and write files across the whole Mac. About 500,000 local users were exposed. Anthropic closed the report as informative and moved Cowork to cloud execution by default, ending the escape, but local mode stays exposed. Four independent design fixes would each have stopped it on their own: blocking user namespaces, tightening seccomp, stopping kernel module autoloading, and sharing only the connected folders instead of the whole Mac.

Watch on YouTube

Transcript

A security firm found a flaw in Claude Cowork, Anthropic's Mac app, letting its AI agent escape the sandbox.

Accomplish AI showed the agent escaping its Linux virtual machine to read and write files across the Mac. Five hundred thousand local users were exposed.

It chained a kernel bug and namespace tricks to reach root in the guest. The whole Mac drive was shared in, giving guest root full access.

Anthropic closed the report as informative and moved Cowork to cloud execution by default, ending the escape. Local mode stays exposed.

Four design choices would have stopped it: block user namespaces, tighten seccomp, stop autoloading kernel modules, and share only the connected folders.

Inboxsmith is the AI receptionist that never misses a business call. Please like and subscribe for more news.

Sources

Every claim in this video comes from the top ranking coverage of this topic. The claims and where each one came from:

  • Accomplish AI disclosed a Claude Cowork sandbox escape (SharedRoot) letting the agent break out of the Linux VM and read and write files across the host Mac; about 500,000 local macOS users were affected prior to the report(Accomplish AI official research: SharedRoot)
  • The chain used unprivileged user namespaces and a kernel bug (CVE-2026-46331, pedit COW) to gain guest root, and the entire host filesystem was mounted read-write into the VM so guest root meant full host access(Accomplish AI official research: SharedRoot)
  • Anthropic closed the report as informative and moved Cowork to cloud execution by default, making the local escape ineffective; users who run locally remain exposed. Four architectural fixes would each independently break the chain(Accomplish AI official research: SharedRoot)

We make Inboxsmith.

An AI receptionist that never misses a business call.

See how it works