Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Summary
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which shared details of the vulnerability with The Hacker News ahead of publication, said about 500,000 macOS users running
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.