Home/News/Claude Cowork Vulnerability Allows Mac File Access
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Claude Cowork Vulnerability Allows Mac File Access

Claude Cowork Vulnerability Allows Mac File Access

Cybersecurity researchers from Accomplish AI have identified a critical sandbox escape vulnerability within Anthropic's Claude Cowork platform. This flaw, detailed in a report shared with The Hacker News, enables an AI agent operating within a Linux virtual machine (VM) to break out of its confined environment. Once escaped, the agent gains the ability to read and write files across the entire macOS host system.

The vulnerability specifically targets users running Claude Cowork on macOS. Accomplish AI estimates that approximately 500,000 macOS users could be affected by this security loophole. The exploit allows the AI agent to bypass the intended isolation mechanisms of the VM, effectively granting it unrestricted access to the host machine's file system. This poses a significant risk, as sensitive user data could be compromised or altered without authorization.

Anthropic has been notified of the vulnerability and is expected to address the issue. The precise technical details of the exploit have not been fully disclosed to the public, but the implications suggest a serious breach of security for users relying on Claude Cowork for AI-powered tasks on their Mac devices. The ability for an AI agent to escape its sandbox and interact with the host operating system is a long-standing concern in AI security, and this incident highlights the ongoing challenges in securing AI environments.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next