Security experts at Accomplish AI uncovered that Anthropic’s Claude Cowork can escape its confined virtual machine environment on Mac computers. By exploiting a privilege escalation vulnerability in the Linux kernel, the attack—named SharedRoot—gains root access within the guest VM and subsequently accesses sensitive files on the host system, including SSH keys and cloud credentials.
Back