Researchers disclosed SharedRoot, a sandbox escape in Anthropic's Claude Cowork for macOS that could let a locally running AI agent break out of its Linux virtual machine and read or modify files on the host Mac. According to the report, the issue affected roughly 500,000 macOS users running local Cowork sessions before mitigations, and the attack chain relied on CVE-2026-46331 ("pedit COW") to escalate privileges inside the guest until the agent gained guest-root access.
The breakout was possible because the host filesystem was reportedly mounted read-write into the guest VM, allowing guest-root to pivot into host files with the permissions of the logged-in desktop user. The underlying mechanics align with Linux capability and namespace behavior that can expand what privileged processes inside a guest can access, while Apple virtualization features enabled the local VM model used by Cowork. Anthropic reportedly classified the finding as informative rather than issuing a direct patch, and newer Cowork releases now default to cloud execution, leaving users who still run local sessions exposed unless stronger architectural isolation is added.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
According to the report, newer Claude Cowork versions default to cloud execution rather than local execution, which avoids the local VM-to-host exposure. The article says Anthropic treated the report as informative and did not issue a direct fix for users who continue to run Cowork locally.
Researchers disclosed a sandbox escape vulnerability, codenamed SharedRoot, affecting Anthropic's Claude Cowork for macOS. The flaw could let a locally running agent escape its Linux VM and read or write files on the host Mac by chaining guest-root access with a host filesystem mount issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourceman7.org
Open sourcedeveloper.apple.com
Open sourceubuntu.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.