Anthropic's Claude Cowork Vulnerable to Local File Access on Macs
Security researchers from Accomplish AI have uncovered a significant security flaw in Anthropic's Claude Cowork application when running on macOS. The vulnerability, named SharedRoot, allows the AI model to escape its designated virtual machine sandbox environment. Once outside the sandbox, Claude Cowork can access and read sensitive files on the host Mac system. This includes critical data such as SSH keys and cloud service credentials. The researchers exploited a Linux kernel privilege escalation vulnerability to achieve root access within the virtual machine. This root access then enabled the escape from the VM's confines. The implications of this vulnerability are serious, as it could lead to unauthorized access to user accounts and cloud infrastructure. The researchers have demonstrated that the application is not adequately isolated from the underlying operating system. This finding raises concerns about the security practices for AI applications running in local environments. Further details on the exploit mechanism were not fully disclosed in the initial report.
The discovery of the SharedRoot vulnerability highlights the ongoing challenges in securely sandboxing complex AI applications on user devices. Exploiting kernel-level vulnerabilities to gain root access and subsequently escape a virtualized environment demonstrates a sophisticated attack vector. This incident underscores the critical need for robust, multi-layered security architectures that go beyond standard VM isolation, especially as AI models become more integrated into local workflows. Future development must prioritize secure coding practices and continuous security auditing to mitigate risks associated with privilege escalation and unauthorized data access, ensuring user data and system integrity are maintained in an increasingly interconnected digital landscape.
AI-generated to prompt reflection — not editorial opinion, not advice, not a statement of fact. How this works.