Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Read full story on The Hacker News
Share
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
AI disclosure

Summary

Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which shared details of the vulnerability with The Hacker News ahead of publication, said about 500,000 macOS users running

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.