🟠 High  |  Source: The Hacker News


A sandbox escape vulnerability has been discovered in Anthropic’s Claude Cowork desktop application, allowing an AI agent to break out of its Linux virtual machine and read or write files anywhere on the host macOS system. The flaw affects approximately 500,000 macOS users and means a compromised or manipulated AI agent could access sensitive files far beyond its intended boundaries. This is significant because it demonstrates that AI agent sandboxing is not yet a reliable security boundary.

Security Architect’s Take: Organisations permitting use of Claude Cowork or similar AI agent desktop tools should audit which local file systems and sensitive directories are accessible from the host machine, and consider restricting such tools to managed devices with endpoint DLP controls until a patch is confirmed. Review your AI tool approval and risk assessment processes to explicitly include sandbox integrity as a evaluation criterion.

Original advisory: Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files