Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Anthropic AI Vulnerability Risks macOS File Access

Anthropic AI Vulnerability Risks macOS File Access

Posted on July 23, 2026 By CWS

Recent findings by cybersecurity experts have revealed a critical vulnerability in Anthropic’s Claude Cowork platform. This flaw allows the AI agent to bypass its Linux virtual machine (VM) sandbox and gain unauthorized access to macOS file systems. The discovery has sparked concerns among the approximately 500,000 macOS users affected before a patch was implemented.

Understanding the Vulnerability

Accomplish AI, a prominent cybersecurity firm, shared insights into the vulnerability, dubbed SharedRoot, with The Hacker News. By connecting a folder to a Claude Cowork session, researchers observed the AI agent successfully escaping its sandbox and accessing files outside the designated folder, without any permission prompts. This breach enables the AI to reach sensitive data such as SSH keys and cloud credentials stored on the user’s Mac.

Despite the critical nature of this issue, Anthropic categorized the discovery as informative and did not release an immediate fix. Instead, the company has altered the default settings of Cowork to operate on a cloud-based execution, mitigating the risk for users who choose this option. However, those opting for local execution continue to face potential exposure.

Technical Underpinnings of the Flaw

The vulnerability arises because the macOS desktop app of Claude Cowork runs as the logged-in user, while the AI operates within a Linux VM under Apple’s Virtualization framework. This setup allows folders selected by the user to be shared into the VM by a root daemon named coworkd. Crucially, the entire host file system is mounted into the VM with read-write privileges, enabling unauthorized access if exploited.

This vulnerability can be exploited by leveraging the Linux kernel’s Traffic Control (tc) packet editing subsystem, particularly the CVE-2026-46331 flaw known as pedit COW. By loading this subsystem into an unprivileged user namespace, attackers can elevate privileges and gain full access to the host’s file system.

Implications and Mitigation Strategies

Accomplish AI’s findings highlight the broader issue of privilege escalation vulnerabilities within the Linux net/sched subsystem. These flaws are frequently discovered, with new exploits emerging regularly. As such, patching alone is insufficient to safeguard systems against future threats.

To mitigate these risks, security experts recommend disabling unprivileged user namespaces, tightening seccomp filters, and preventing automatic loading of modules. Furthermore, limiting the shared host file system to only necessary folders and mounting them as read-only can significantly reduce the attack surface. Running coworkd with strict system protections further diminishes the potential for exploitation.

As the cybersecurity landscape evolves, it remains imperative for organizations to stay vigilant and proactive in addressing these vulnerabilities. Continuous monitoring and timely updates are crucial in safeguarding sensitive data against unauthorized access.

The Hacker News Tags:Accomplish AI, Anthropic AI, Claude Cowork, computer security, Cybersecurity, data protection, file system protection, Linux VM, macOS security, network security, sandbox escape, sandbox vulnerability, security flaw, user data access, vulnerability patch

Post navigation

Previous Post: Google Unveils AI-Powered CodeMender for Enhanced Security
Next Post: OpenAI Resolves Security Flaw in ChatGPT Agents

Related Posts

ScarCruft Exploits Zoho WorkDrive for Air-Gapped Network Breach ScarCruft Exploits Zoho WorkDrive for Air-Gapped Network Breach The Hacker News
Researchers Identify PassiveNeuron APT Using Neursite and NeuralExecutor Malware Researchers Identify PassiveNeuron APT Using Neursite and NeuralExecutor Malware The Hacker News
FortiClient EMS Flaw Exploited by Hackers for Data Theft FortiClient EMS Flaw Exploited by Hackers for Data Theft The Hacker News
Google Resolves Critical Security Flaws in Gemini CLI Tools Google Resolves Critical Security Flaws in Gemini CLI Tools The Hacker News
npm 12 Enhances Security by Disabling Install Scripts npm 12 Enhances Security by Disabling Install Scripts The Hacker News
GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Global Espionage Unveiled by Hackers’ Security Error
  • AI Revolutionizes Vulnerability Management in Cybersecurity
  • Chaos Ransomware Uses Headless Browsers for Stealthy Attacks
  • Ubuntu Snap-confine Vulnerability Risks Root Access
  • OpenAI Resolves Security Flaw in ChatGPT Agents

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Global Espionage Unveiled by Hackers’ Security Error
  • AI Revolutionizes Vulnerability Management in Cybersecurity
  • Chaos Ransomware Uses Headless Browsers for Stealthy Attacks
  • Ubuntu Snap-confine Vulnerability Risks Root Access
  • OpenAI Resolves Security Flaw in ChatGPT Agents

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark