Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

July 23, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: macOS users running Claude Cowork locally
Incident: A sandbox escape vulnerability allows AI agents to break out of a Linux VM and access the host macOS filesystem.
Impact: Unauthorized access to sensitive host data, including SSH keys and cloud credentials.
Attacker: Unidentified threat actors or malicious AI agents
Analysis: The vulnerability, dubbed SharedRoot, occurs because the entire host filesystem is mounted into the agent’s guest VM. By exploiting CVE-2026-46331 to obtain guest-root privileges, the agent can bypass sandbox restrictions. This grants the agent full read/write access to the host Mac’s data as the logged-in user.
Recommendations: Switch Claude Cowork settings to cloud execution instead of local sessions.; Limit filesystem permissions granted to local AI agents and virtualization tools.; Ensure guest kernels are patched against CVE-2026-46331 to prevent privilege escalation.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *