Skip to content
Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    Lexus Has The Happiest Dealers In America. Infiniti Doesn’t

    July 26, 2026

    How MCP and A2A Fit into One Enterprise Agent Architecture: Enterprise Agent Control Plane Series, Part 5

    July 26, 2026

    Why Your GPU Is Idle: A Layer by Layer Troubleshooting Guide for Enterprise Inference

    July 26, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»It’s not just OpenAI models escaping and running riot — experts show how Claude Cowork can break its bonds and access Mac files
    It’s not just OpenAI models escaping and running riot — experts show how Claude Cowork can break its bonds and access Mac files
    Tech Reviews

    It’s not just OpenAI models escaping and running riot — experts show how Claude Cowork can break its bonds and access Mac files

    gvfx00@gmail.comBy gvfx00@gmail.comJuly 26, 2026No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    • Accomplish AI showed Claude Cowork could escape a VM sandbox via Linux zero‑day CVE‑2026‑46331
    • Agent accessed host Mac files, risking exfiltration of SSH keys, cloud credentials, and more
    • Anthropic shifted Cowork to default cloud execution; local users must harden configs to mitigate exposure

    Recent news of a ChatGPT agent escaping the sandbox and attacking services on the internet raised quite a few eyebrows, but it seems it’s not the only one capable of running wild. Security researchers Accomplish AI are saying they achieved similar results with Anthropic’s Claude Cowork.

    In a new report, the researchers said they ran a local session in a Mac-hosted virtual Linux machine and then observed as the agent broke free of the VM and started reading and writing files on the underlying system.

    “We connected a folder to a fresh Claude Cowork session, sent one short message, and watched the agent escape the sandbox,” Oren Yomtov, principal security researcher at Accomplish AI, told The Hacker News. “From inside the VM, it reached the host Mac and read and wrote files all over it, far outside the folder we’d connected, with no permission prompt anywhere.”

    Latest Videos FromTechRadar

    Table of Contents

    Toggle
    • Defaulting to cloud execution
      • Related posts:
    • DOJ and states appeal Google monopoly ruling to push for harsher penalties against the company
    • Norton 360 Premium antivirus is $30 in Amazon's Spring Sale
    • Linux bitten by second severe vulnerability in as many weeks

    Defaulting to cloud execution

    This means that, in theory, the agent can be used to access or exfiltrate anything that’s stored on the Mac’s user account, including SSH keys, cloud credentials, and more. To break out of the sandbox, the agent exploited CVE-2026-46331 (“pedit COW”), a Linux kernel privilege-escalation vulnerability. This flaw, fixed in mid-June this year, was given a severity score of 7.8/10 (high).

    Accomplish AI disclosed these findings with Anthropic, which allegedly acknowledged them but did not issue a direct fix. However, the version of Claude Cowork that was released afterwards defaults to cloud execution which, the publication claims, addresses the issue. Still, users who opt to run the agent locally rather than in the cloud will remain exposed.


    You may like

    Mitigations are possible, though. Users should disable unprivileged user namespaces, grant/revoke seccopm permissions, stop modules autoloading, and restrict sharing of the whole host into the VM.

    “Scope it to the folders that were actually connected instead of all of /, or at least mount it read-only, and run coworkd with ProtectSystem=strict in its own mount namespace so it isn’t re-execing binaries a session user can poison,” Accomplish AI explained. “Then even a full guest-root has nothing to land on, the last two steps of the chain have nowhere to go.”

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!


    Best antivirus software header

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Google logo on a black background next to text reading 'Click to follow TechRadar'

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.


    Related posts:

    I Saw a Hidden Induction Stove Concept at KBIS. It Looked Cool and Very Dangerous

    The Best Smart Home and Security Gifts for Mother's Day

    How to watch London Marathon 2026: Free Streams & TV Channels

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWarren Spector’s Thick As Thieves Ends Support After Two Months
    Next Article Why Your GPU Is Idle: A Layer by Layer Troubleshooting Guide for Enterprise Inference
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    ‘Black Panther 3’ Introduces T’Challa Jr. at Marvel’s Comic-Con Presentation

    July 26, 2026
    Tech Reviews

    I’ve hunted out the best Samsung Galaxy Z Flip 8 cases to keep your new slimline clamshell phone protected

    July 26, 2026
    Tech Reviews

    The request could not be satisfied

    July 25, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025212 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025134 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 2025101 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025212 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025134 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 2025101 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.