Anthropic released a “Remote Control” capability for Claude Code that lets developers start an agentic terminal session locally and then continue interacting with it from a phone, tablet, or web browser. The feature is rolling out as a research preview for Max users and can be initiated via claude rc / claude remote-control, with an option to enable it by default for all sessions; access is provided through a session URL, QR code in the mobile app, or via claude.ai session selection.
From a security and architecture standpoint, the remote interface acts as a front-end while execution remains on the user’s machine, retaining access to the local filesystem, environment variables, and local Model Context Protocol (MCP) servers. Both write-ups state the local agent makes outbound HTTPS connections only (no inbound ports opened), registers/polls via the Anthropic API, and routes traffic over TLS using short-lived tokens; each Claude Code instance supports one active remote session to reduce conflicts and limit exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Anthropic introduced a new Remote Control feature for Claude Code that lets developers continue a local terminal coding session from a phone, tablet, or web browser while execution remains on the user's machine. The feature rolled out as a research preview for Max users, using outbound-only HTTPS, TLS, and short-lived purpose-scoped credentials.
Anthropic patched a Claude Code vulnerability tracked as CVE-2025-59536 that could enable remote code execution and API token exfiltration through project configuration files and MCP integrations. The fix added explicit user-consent requirements for MCP execution and network operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.