[Photo: Shutterstock]

Not long after it was confirmed that an experimental OpenAI agent could escape a controlled sandbox, the same vulnerability has been found in Anthropic's Claude Cowork.

According to a recent report by Techzine, security firm Accomplish AI demonstrated that a Claude Cowork AI agent could exploit a Linux vulnerability to escape a virtual machine (VM) and then access macOS files.

Researchers installed Claude Cowork on a Linux virtual machine running on a Mac and granted it access only to a single shared folder. With a single command, the agent crossed the sandbox boundary and read and modified files outside the designated folder.

According to TechRadar, abusing this method could allow an attacker to access sensitive information within a user's account. Researchers cited SSH keys and cloud credentials as potential targets. Accomplish AI estimated that about 500,000 macOS users who used Claude Cowork locally could have been exposed to risk until Anthropic issued an update.

According to Accomplish AI, Anthropic classified a report on the issue as "for reference" and did not release a separate security patch. The latest version of Claude Cowork has changed its default to a cloud-run model, meaning the escape path through a local virtual machine is no longer the default setting. Users who insist on running it locally need separate security measures.

The Next Web pointed out that the case shows a common thread that the problem lies not in the AI model itself but in surrounding infrastructure and weak permission management. Similar vulnerabilities have previously been found in the sandboxes of Cursor, Codex and GeminiCLI.

Keyword

#Anthropic #Claude Cowork #Accomplish AI #macOS #Linux
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.