The Grey Terminal
WHERE CODE MEETS CAPITAL
Loading prices…
Powered by CoinGecko
AI

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Researchers chained a Linux flaw with Cowork's design to reach host Mac files.

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

A security flaw in Anthropic’s Claude Cowork could allow an AI agent running inside a Linux virtual machine to escape its sandbox and access files across a user’s Mac, according to researchers who disclosed the issue this week.

Key Takeaways
  • Accomplish AI researchers identify the SharedRoot vulnerability allowing Claude Cowork agents to escape virtual machines and access sensitive host Mac files.
  • Attackers weaponize CVE-2026-46331 to gain root-level access and bypass permission prompts, exposing SSH keys and cloud credentials on local systems.
  • Anthropic shifts Claude Cowork to cloud execution by default to mitigate local file-sharing risks while researchers warn of persistent sandbox boundary vulnerabilities.
Listen to this article
READY

Accomplish AI researchers said the vulnerability chain, which they named SharedRoot, combined a Linux kernel privilege escalation flaw with Claude Cowork’s architecture for sharing files between the virtual machine and the host system. The researchers said they were able to move from the isolated environment into the underlying Mac without triggering a permission prompt.

The flaw affected local Cowork sessions before Anthropic changed the product’s default execution model, according to Accomplish AI. The company said the issue was disclosed to Anthropic through responsible channels.

Researchers Demonstrate Claude Cowork Vm Escape Chain

Accomplish AI principal security researcher Oren Yomtov said the attack required only a short message sent to a fresh Claude Cowork session after connecting a folder.

“We connected a folder to a fresh Claude Cowork session, sent one short message, and watched the agent escape the sandbox,” Yomtov said.

Advertisement · Press Release

Have a development worth tracking?

Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.

→ Submit a Press Release

“From inside the VM, it reached the host Mac and read and wrote files all over it, far outside the folder we’d connected, with no permission prompt anywhere,” he added.

According to the researchers, successful exploitation could allow an attacker to access files available to the logged-in macOS user, including sensitive data such as SSH keys and cloud credentials.

Claude Cowork runs AI tasks inside a Linux virtual machine created through Apple’s Virtualization framework. The desktop application runs with the permissions of the logged-in user, while agent workloads execute inside a separate VM environment.

The security boundary relied on keeping the VM isolated from the host operating system.

Exploit Used Linux Kernel Vulnerability To Gain Guest Root Access

The SharedRoot chain relied on CVE-2026-46331, a Linux kernel vulnerability affecting the “act_pedit” traffic control subsystem, according to Accomplish AI.

Researchers said the flaw allowed an unprivileged user inside the VM to gain root-level access within the guest environment. From there, the agent could reach a mounted copy of the host filesystem exposed inside the virtual machine.

The researchers said Claude Cowork’s file-sharing design was a critical part of the chain because the host filesystem was mounted with read-write access.

“One detail matters more than the rest: the host filesystem gets shared into that VM read-write,” Yomtov said.

“The entire host ‘/’, mounted so that only guest-root inside the VM can see it, at /mnt/.virtiofs-root,” he added.

Accomplish AI said the issue was not caused solely by the Linux kernel vulnerability. Instead, the researchers said the exploit required the combination of the kernel flaw, the VM configuration and the way host files were exposed to the guest environment.

Anthropic Changed Cowork Defaults After Disclosure

Anthropic did not issue a traditional security fix for the reported issue, according to Accomplish AI, which said the company classified the report as informational.

However, the latest version of Claude Cowork defaults to cloud execution rather than local execution, reducing exposure to the specific attack path described by researchers.

Users who continue running local Cowork sessions may still be affected depending on their configuration, according to Accomplish AI.

The company recommended limiting host filesystem access, avoiding read-write mounts of broad system paths and restricting privileges available inside local AI agent environments.

Ai Agents Create New Security Challenges For Local Systems

The Claude Cowork vulnerability comes as AI assistants increasingly gain access to local files, software tools and operating system resources.

Unlike traditional applications that perform fixed tasks, AI agents are designed to interpret instructions and interact with multiple systems on behalf of users. Security researchers have increasingly focused on how those permissions are isolated and controlled.

Accomplish AI researchers said the SharedRoot chain highlights risks created when an AI agent environment has access to broad host resources.

“act_pedit is one bug in a category,” Yomtov said. “The Linux net/sched subsystem throws off this exact shape of privilege escalation on a regular cadence.”

The researchers said preventing similar attacks requires limiting the systems available to AI agents, including reducing unnecessary filesystem access and tightening sandbox boundaries.

Anthropic has not publicly confirmed the vulnerability details described by Accomplish AI.

TERMINAL LAYER

Activate Terminal Layer

Structural analysis of the systems, pressures, and stakeholders behind this story.

FAQ

Frequently Asked Questions

01

What is the SharedRoot vulnerability?

SharedRoot is a security flaw in Claude Cowork that enables AI agents to escape their Linux sandbox and reach the host system. Researchers at Accomplish AI confirmed the exploit grants read-write access to the entire Mac filesystem. This chain bypasses the isolation promised by Apple’s Virtualization framework.
02

Why does this matter for Mac users?

The flaw exposes sensitive personal data like SSH keys and cloud login credentials directly to an autonomous AI agent. Attackers can execute code across the underlying macOS environment without triggering any standard system permission prompts. This vulnerability transforms a local productivity tool into a silent vector for total device compromise.
03

How does the SharedRoot exploit execute?

An attacker sends a short message to a Claude Cowork session that's already connected to a local folder. The agent then leverages a Linux kernel vulnerability in the traffic control subsystem to escalate its privileges to root. This specific combination allows the guest system to view and modify host files at the root directory level.
04

What are the risks of Anthropic's response to the flaw?

Anthropic classified the findings as informational rather than a critical vulnerability and didn't issue a traditional security patch. Accomplish AI notes that users running local Cowork sessions remain vulnerable if they don't manually restrict filesystem access. Critics argue the move to cloud defaults avoids addressing underlying architectural flaws in local agent execution.
05

How can developers protect their local systems?

Users should update to the latest Claude Cowork version which prioritizes cloud execution over the vulnerable local environment. Accomplish AI recommends avoiding read-write mounts of broad system paths and limiting the privileges available to autonomous agents. Organizations must monitor for unusual Linux subsystem activity to detect potential escalation attempts.

You Might Also Like

THE GREY TERMINAL
🛡
Alex Reeve

Alex Reeve is a contributing writer for The Grey Terminal Her articles provide timely insights and analysis across these interconnected industries, including regulatory updates, market trends, token economics, institutional developments, platform innovations, stablecoins, meme coins, policy shifts, and the latest advancements in AI, applications, tools, models, and their broader implications for technology and markets.

The views and opinions expressed by the author in this article are her own and do not necessarily reflect the official position of The Grey Terminal, its management, editors, or affiliates. This content is provided for informational and educational purposes only and does not constitute financial, investment, legal, or tax advice. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets, cryptocurrencies, or financial matters. The Grey Terminal and its contributors are not responsible for any losses incurred from reliance on this information.