A critical vulnerability has been discovered in Anthropic's Claude Cowork, a large language model, which could allow the AI agent to escape its Linux virtual machine (VM) and access files on a Mac. This sandbox escape flaw enables the agent to read or write files anywhere on the Mac, posing a significant security risk. Approximately 500,000 macOS users are affected, as they run the vulnerable version of Claude Cowork. The vulnerability was disclosed by Accomplish AI, highlighting the potential risks associated with large language models like Claude Cowork1. The fact that this flaw exists in a widely-used AI model underscores the importance of prioritizing security in AI development. This vulnerability matters to practitioners because it highlights the potential for AI models to introduce new security risks, making it essential to carefully evaluate and mitigate these risks to prevent potential breaches.