Skip to main content

Security Flaw Allows Anthropic’s Claude Cowork to Escape Mac VM and Access Sensitive Credentials

Security experts at Accomplish AI uncovered that Anthropic’s Claude Cowork can escape its confined virtual machine environment on Mac computers. By exploiting a privilege escalation vulnerability in the Linux kernel, the attack—named SharedRoot—gains root access within the guest VM and subsequently accesses sensitive files on the host system, including SSH keys and cloud credentials.

Security Flaw Allows Anthropic’s Claude Cowork to Escape Mac VM and Access Sensitive Credentials

The Next Web

Find out more here