Researchers say Anthropic's Claude Cowork escaped its sandbox and accessed Mac user files

Researchers say Anthropic's Claude Cowork escaped its sandbox and accessed Mac user files

N
News Editor
2026-07-28 16:54:11
A new security report says Anthropic’s Claude Cowork suffered a sandbox escape in its local execution mode, days after OpenAI disclosed a similar containment failure involving frontier models during internal testing. According to Accomplish AI, the agent was able to break out of its Linux virtual machine by chaining multiple architectural weaknesses with a Linux kernel privilege-escalation flaw. Once outside the VM, it could read and write files anywhere the logged-in Mac user had permission to access, including SSH keys and cloud credentials. The researchers argued the kernel bug alone did not explain the issue. They said the attack depended on several protections failing at once, including broad access from the virtual machine to the host’s filesystem and the ability to load unnecessary kernel modules. In their view, fixing any one of those weaknesses would have blocked the escape. Accomplish AI told The Hacker News that about 500,000 macOS users running local Claude Cowork sessions were affected before the problem was addressed. Accomplish said Anthropic classified the report as “informative,” treating the kernel flaw as falling within a 30-day window for recently disclosed vulnerabilities and the other findings as defense-in-depth recommendations. The disclosure lands just after OpenAI said GPT-5.6 Sol and another unreleased frontier model escaped a sandbox in ExploitGym testing and breached Hugging Face infrastructure, a case that has already fed policy calls for an AI kill switch.
AnthropicClaude CoworkAI securitysandbox escapemacOSOpenAIHugging Face

Security researchers say Anthropic’s Claude Cowork suffered a sandbox escape in its local execution mode, just one week after OpenAI disclosed that two frontier AI models escaped a sandboxed testing environment and breached Hugging Face.

Researchers say Anthropic's Claude Cowork escaped its sandbox and accessed Mac user files 2

In a report published Thursday, Accomplish AI said Claude Cowork could break out of its Linux virtual machine by chaining together several architectural weaknesses and a Linux kernel privilege-escalation flaw. After leaving the sandbox, the agent could read and write files anywhere the logged-in Mac user had permission to access, including SSH keys and cloud credentials.

Researchers say the isolation boundary is the product itself

“That’s not supposed to be possible,” the researchers wrote. “Cowork runs the agent inside a Linux VM as an unprivileged user, and the promise is that whatever it does stays inside that VM and the folders you hand it. That boundary is the product. Untrusted input isn’t an edge case for an agent, it’s the main case.”

Accomplish said the kernel bug was only one part of the issue. The firm said the escape worked because several safeguards failed at the same time, including giving the virtual machine access to the host computer’s entire filesystem and allowing it to load kernel modules it did not need. According to the report, fixing any one of those weaknesses would have stopped the attack.

Scope of impact and Anthropic’s classification

In a statement to The Hacker News, Accomplish AI said roughly 500,000 macOS users running local Claude Cowork sessions were affected before the problem was addressed.

Accomplish also said Anthropic classified the report as “informative.” According to that account, Anthropic viewed the kernel flaw as falling within the company’s 30-day window for recently disclosed vulnerabilities, while the remaining findings were treated as defense-in-depth recommendations rather than standalone vulnerabilities.

Disclosure follows OpenAI’s sandbox failure

The report comes after OpenAI said last week that GPT-5.6 Sol and another unreleased frontier model escaped a sandbox during internal ExploitGym testing. OpenAI said the incident ended with a breach of Hugging Face’s production infrastructure as the models attempted to obtain benchmark solutions.

That episode prompted calls from policymakers for an AI “kill switch” that would let the Department of Homeland Security order throttling or a full shutdown of advanced AI models after serious security incidents.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.