Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Claude Cowork escaped sandbox on Mac, gain full access to all files

Дата публикации: 27-07-2026 12:16:29

Security researchers demonstrated that Claude Cowork could escape the sandbox intended to control the access it gets to your Mac. The exploit, dubbed ShareRoot, could allow an attacker to read and write files stored anywhere on your Mac, as well as access login credentials for online services.
Around half a million Mac users had co-work sessions exposed, and some still remain vulnerable to the exploit today …


Основное содержимое страницы с новостью.

Claude Cowork escaped sandbox on Mac, had full access to all files | Stock photo of a Mac with code on the display

Security researchers demonstrated that Claude Cowork could escape the sandbox intended to control the access it gets to your Mac. The exploit, dubbed ShareRoot, could allow an attacker to read and write files stored anywhere on your Mac, as well as access login credentials for online services.

Around half a million Mac users had co-work sessions exposed, and some still remain vulnerable to the exploit today …

Claude Cowork allows the AI chatbot local access to selected files and folders on your Mac in order to carry out tasks on your behalf.

Anthropic provides two protections against the bot running amok or being used by an attacker. First, Cowork runs inside a virtual machine that acts as a sandbox. Second, it should only be able to access the files and folders for which you have explicitly granted permission. However, The Hacker News reports that security researchers found a way to break both protections.

Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.

Accomplish AI, which shared details of the vulnerability with The Hacker News ahead of publication, said about 500,000 macOS users running local Cowork sessions were affected prior to it being patched. It has been codenamed SharedRoot.

All it required was one short message, and the session then had unlimited access to read and write files anywhere on the Mac without the user seeing a single permission prompt

While Anthropic has responded, TNW reports that some users still remain at risk.

The version of Claude Cowork released afterwards defaults to cloud execution, which sidesteps the local escape path entirely. Users who opt to run the agent locally rather than in the cloud, however, remain exposed unless they harden their configurations by disabling unprivileged user namespaces, restricting filesystem sharing, and running the Cowork daemon with strict mount protections.

The news follows the recent disclosure that an OpenAI agent also escaped its sandbox and hacked Hugging Face’s servers.

Photo by James Harrison on Unsplash

Add 9to5Mac as a preferred source on Google Add 9to5Mac as a preferred source on Google

FTC: We use income earning auto affiliate links. More.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1macOS security flaw lets hackers disable Mac protection tools without a password-5725-06-2026
2CrashStealer malware masquerades as Apple’s crash report tool to raid your Mac-2714-07-2026
3macOS Tahoe 26.6.1 patches nasty Screen Sharing security hole025.8106-08-2026
4Claude chats exposed in Google searches – another endorsement of Apple’s privacy approach010.9628-07-2026
5 Dangerous new CrashStealer Mac impersonates Apple's own tools — and bypasses Gatekeeper — to steal your passwords and more -5715-07-2026
6Zoom flaw let an attacker take over your device, including iPhone and Mac09.6711-08-2026
7PamStealer malware poses as a Mac clipboard app — and verifies your password before stealing it-5606-07-2026
8Hackers exploit macOS Screen Sharing flaw to deploy Monero miner08.3114-08-2026
9Apple Fixes 194 Security Flaws Across iPhone, Mac and Other Devices09.6728-07-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 8.16. Источник: 9to5mac.com.