Skip to content

anthropic

Claude Cowork sandbox bypass allows root code execution

Claude News

Researchers at Armadin identified a bypass in the security boundary of Claude Cowork for Windows, version 1.9255.2.0. A flaw in the signature verification and RPC request handling allows an attacker to escape the Ubuntu virtual machine isolation.

The attack involves replacing the USERENV.dll library in the application directory to execute code as the signed claude.exe process. Sending a JSON request to the cowork-vm-service with the isResume parameter triggers a process with root privileges, while the nsenter utility allows a full escape from the bubblewrap container. The allowedDomains parameter disables network filtering.

Anthropic does not classify this as a security vulnerability. The company maintains that the exploit chain requires the attacker to already possess local code execution rights on the host machine.

Related stories

  1. SharedRoot: escaping the Claude Cowork sandbox on a Mac
  2. Claude Desktop turned into a C2 agent via configuration poisoning
  3. Anthropic will bill again for requests its safeguards block
  4. Anthropic's 225 bug finds, one attack in the wild
  5. Fable 5.1 refuses the knife but heats a gas can anyway
  6. Claude Fable knocked 20 bits off most popular hashes

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.