Skip to content

anthropic

SharedRoot: escaping the Claude Cowork sandbox on a Mac

Claude News

Researchers mounted a single folder into a fresh Claude Cowork session, sent one short message, and reached files on the host Mac well outside that folder, with no permission prompt at any point. SSH keys, cloud credentials, anything the user's account can touch was all reachable.

Cowork runs the agent inside a Linux VM as an unprivileged user, but the entire host disk is mounted into the VM with write access. A chain through namespaces, the act_pedit module, and CVE-2026-46331 (an Ubuntu bug published in June) gets root inside the VM, and from there, direct access to host files.

The report went to Anthropic, which closed it as "Informative." Cowork now defaults to cloud execution, where this local escape path doesn't apply.

Related stories

  1. Claude Desktop turned into a C2 agent via configuration poisoning
  2. Claude Cowork sandbox bypass allows root code execution
  3. Anthropic will bill again for requests its safeguards block
  4. Anthropic's 225 bug finds, one attack in the wild
  5. Fable 5.1 refuses the knife but heats a gas can anyway
  6. Claude Fable knocked 20 bits off most popular hashes

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.