Threat · curated 23 Jul 2026

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Coverage timeline

23 Jul 2026thehackernews.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

SharedRoot shows how an AI coding agent's sandbox can be trivially escaped to grab host credentials, turning a convenience tool into a full local data-exfiltration vector on hundreds of thousands of machines.

Researchers at Accomplish AI disclosed SharedRoot (CVE-2026-46331), a sandbox escape vulnerability in Anthropic's Claude Cowork that lets the AI agent break out of its Linux VM and read or write arbitrary files on the host Mac. A single message to a fresh session let the agent reach files far outside the connected folder with no permission prompt, exposing SSH keys, cloud credentials, and other data; roughly 500,000 macOS users were affected before Anthropic patched it.