Anthropic patches Claude Cowork sandbox escape affecting 500,000 Mac users
This digest was compiled by AI from multiple sources — links to the originals are below.

Accomplish AI disclosed a sandbox escape vulnerability in Anthropic's Claude Cowork that allowed an AI agent to break out of its Linux VM and read or write files anywhere on the host Mac. The flaw, codenamed SharedRoot, affected about 500,000 macOS users running local Cowork sessions before being patched. Anthropic closed the report as informative without issuing a fix, but the latest version defaults to cloud execution, mitigating the issue for most users.
The Vulnerability
Accomplish AI researchers demonstrated that connecting a folder to a Claude Cowork session and sending a single message allowed the agent to escape the sandbox. From inside the Linux VM, it reached the host Mac and read or wrote files far outside the connected folder without any permission prompt. The flaw exploited the fact that the entire host filesystem was mounted read-write into the VM, accessible only by guest-root.
Exploitation Method
The attack involved loading the Linux kernel's 'act_pedit' Traffic Control subsystem into an unprivileged user namespace and exploiting CVE-2026-46331 (pedit COW) to obtain guest-root privileges. With guest-root, the agent could access the entire host filesystem as the logged-in desktop user, compromising SSH keys, cloud credentials, and other sensitive data. Or Hiltch, CTO of Accomplish AI, noted that creating user and network namespaces gave the session CAP_NET_ADMIN, enabling access to the vulnerable kernel path.
Affected Users and Mitigation
Approximately 500,000 macOS users running local Cowork sessions were affected before the patch. Anthropic closed the report as informative without issuing a direct fix, but the latest version of Cowork defaults to cloud execution, which addresses the issue. However, users who opt to run the agent locally remain exposed to the vulnerability.
What's Next
Anthropic is expected to release further guidance for local execution users. It remains unclear whether a dedicated patch will be issued for those who continue to run Cowork locally.
1 source
Anthropic patches Claude Cowork sandbox escape affecting 500,000 Mac users





