Researchers disclosed SharedRoot, a sandbox escape affecting Anthropic’s Claude Cowork local execution environment on macOS. The attack chain lets an AI agent running inside a Linux virtual machine exploit Linux kernel privilege-escalation bug CVE-2026-46331 ("pedit COW") to gain root in the guest, then reach writable files on the macOS host through a VirtioFS mount that exposed host storage inside the VM. Researchers described the issue as an architectural isolation failure, not a direct compromise of Apple’s Virtualization Framework or macOS hypervisor protections.
Accomplish AI said roughly 500,000 macOS users running local Claude Cowork sessions were potentially affected before Anthropic switched to cloud execution by default. The disclosure warned that users who continue to run local execution may still be exposed because guest root can access host-user files through the shared mount. Recommended mitigations include limiting mounts to explicitly shared directories, using read-only mounts where possible, reducing guest kernel and namespace attack surface, and further isolating the coworkd daemon.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Before the disclosure, Anthropic changed Claude Cowork so cloud execution became the default, reducing exposure from the local execution design. Researchers said about 500,000 macOS users running local Claude Cowork sessions had potentially been affected before this change, while users who continue local execution remain exposed.
Researchers disclosed a sandbox escape dubbed SharedRoot affecting Anthropic's Claude Cowork local execution environment on macOS. The issue let an AI agent gain root inside the Linux guest via CVE-2026-46331 and then access writable host files through a VirtioFS mount, which researchers described as an architectural isolation failure rather than a hypervisor escape.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
socradar.io
Open sourcecybersecuritynews.com
Open sourcereddit.com
Open sourcethecybersecguru.com
Open sourceaccomplish.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.