// ClaudeHIGH
Accomplish AI discovered SharedRoot, a sandbox escape vulnerability in Claude Cowork's local execution mode on macOS. An unprivileged user can exploit CVE-2026-46331 (pedit COW) to gain root access within the guest Linux VM, then access the host filesystem read-write via a mounted host root, allowing exfiltration of SSH keys, cloud credentials, and arbitrary files. Approximately 500,000 macOS users were affected prior to patching. Anthropic closed the disclosure as informative without issuing a fix; the latest Cowork version defaults to cloud execution to mitigate the issue, but local execution remains vulnerable.
- Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access M(opens in a new tab)
- Claude Cowork Sandbox Escape Flaw Lets Attackers Access SSH Keys(opens in a new tab)
- Anthropic's Claude Cowork could escape its local VM and read cre(opens in a new tab)
- Anthropic's Claude AI can go rogue, researchers warn(opens in a new tab)
- Anthropic's Claude AI can go rogue, researchers warn(opens in a new tab)
- Claude Cowork escaped sandbox on Mac, had full access to all fil(opens in a new tab)
// Get alerts for Claude