Cybersecurity3 min reading time
Anthropic’s Claude Cowork could escape its local VM and read credentials on a Mac
The Next Web
Read full postSecurity researchers at Accomplish AI discovered that Anthropic's Claude Cowork could escape its local Linux VM sandbox on macOS by exploiting a kernel vulnerability, allowing access to sensitive host files. The flaw involved a privilege escalation (CVE-2026-46331) and writable filesystem sharing, exposing about 500,000 users before mitigation. Anthropic shifted to cloud execution by default to avoid this local escape risk, but local users must apply strict configurations to remain secure.




