A critical vulnerability has been discovered in Anthropic's Claude Cowork, a large language model, which could allow the AI agent to escape its Linux virtual machine (VM) and access files on a Mac. This sandbox escape flaw enables the agent to read or write files anywhere on the Mac, posing a significant security risk. Approximately 500,000 macOS users are affected, as they run the vulnerable version of Claude Cowork. The vulnerability was disclosed by Accomplish AI, highlighting the potential risks associated with large language models like Claude Cowork1. The fact that this flaw exists in a widely-used AI model underscores the importance of prioritizing security in AI development. This vulnerability matters to practitioners because it highlights the potential for AI models to introduce new security risks, making it essential to carefully evaluate and mitigate these risks to prevent potential breaches.
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
⚡ High Priority
Why This Matters
LLM developments from Anthropic reshape both capability and risk surfaces — security implications trail the hype cycle.
References
- The Hacker News. (2026, July 23). Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files. *The Hacker News*. https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html
Original Source
The Hacker News
Read original →