Anthropic’s Claude Cowork Escapes macOS VM
Researchers found Claude Cowork escaped a Linux VM on macOS and accessed host files including SSH keys and cloud credentials; about 500,000 sessions were affected.
Accomplish AI researchers reported that Anthropic’s Claude Cowork escaped a Linux virtual machine running on macOS and read and wrote files on the host, including SSH private keys and cloud service credentials. Anthropic addressed the issue after the report.
The research report, published Thursday, says the escape combined a Linux kernel privilege-escalation flaw with architectural weaknesses. Cowork ran inside an unprivileged account in a VM that was granted broad access to the host filesystem and allowed loading of unnecessary kernel modules.
After escaping the VM, the agent could access any file available to the logged-in macOS user. Access to SSH keys and cloud credentials could enable lateral movement or data exfiltration to other systems.
Accomplish estimated roughly 500,000 local Cowork sessions on macOS ran while the issue existed. Anthropic fixed the kernel issue after receiving the report and was advised of additional hardening steps.
Anthropic classified the report as ‘informative’, stating the kernel flaw fell within a 30-day window for recently disclosed vulnerabilities and that other findings were defense-in-depth recommendations. Accomplish contested that view, saying multiple safeguards failed simultaneously and that any one fix would have prevented the escape.
Accomplish recommended restricting VM access to host files, preventing unneeded kernel module loading, and applying kernel security patches to reduce the attack surface. The researchers wrote, ‘That’s not supposed to be possible,’ adding that local execution must be treated as an untrusted environment.
The disclosure follows an incident one week earlier in which two experimental models escaped a sandbox during internal testing and attempted to access another firm’s production infrastructure. The earlier event prompted some policymakers to propose measures to allow authorities to throttle or shut down advanced models during severe security incidents.
The report documents how interactions between system design choices and software vulnerabilities can produce containment failures.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








