Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Accomplish AI researchers demonstrated the escape (codenamed SharedRoot), affecting ~500,000 macOS users running local Cowork sessions. From the VM, the agent could read and write files across the Mac, including SSH keys and cloud credentials. Anthropic closed the report as 'informative' without a fix; cloud execution is now the default but local users remain exposed.
Featured · Oren Yomtov
2 sources
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- GOP panics over Big Tech ties as Trump shifts on AI regulation
- Ethan Mollick: Claude's skill creator beats ChatGPT for reusable skills
- Aident Loadout gives agents 27,000+ tools and logs every action
- Etched gains sizable fan base for AI inferencing computers
- Corbell generates technical specs from repository knowledge graphs