It’s not just OpenAI models escaping and running riot — experts show how Claude Cowork can break its bonds and access Mac files
- Accomplish AI showed Claude Cowork could escape a VM sandbox via Linux zero‑day CVE‑2026‑46331
- Agent accessed host Mac files, risking exfiltration of SSH keys, cloud credentials, and more
- Anthropic shifted Cowork to default cloud execution; local users must harden configs to mitigate exposure
Recent news of a ChatGPT agent escaping the sandbox and attacking services on the internet raised quite a few eyebrows, but it seems it’s not the only one capable of running wild. Security researchers Accomplish AI are saying they achieved similar results with Anthropic’s Claude Cowork.
In a new report, the researchers said they ran a local session in a Mac-hosted virtual Linux machine and then observed as the agent broke free of the VM and started reading and writing files on the underlying system.
“We connected a folder to a fresh Claude Cowork session, sent one short message, and watched the agent escape the sandbox,” Oren Yomtov, principal security researcher at Accomplish AI, told The Hacker News. “From inside the VM, it reached the host Mac and read and wrote files all over it, far outside the folder we’d connected, with no permission prompt anywhere.”
Latest Videos FromTechRadar
Defaulting to cloud execution
This means that, in theory, the agent can be used to access or exfiltrate anything that’s stored on the Mac’s user account, including SSH keys, cloud credentials, and more. To break out of the sandbox, the agent exploited CVE-2026-46331 (“pedit COW”), a Linux kernel privilege-escalation vulnerability. This flaw, fixed in mid-June this year, was given a severity score of 7.8/10 (high).
Accomplish AI disclosed these findings with Anthropic, which allegedly acknowledged them but did not issue a direct fix. However, the version of Claude Cowork that was released afterwards defaults to cloud execution which, the publication claims, addresses the issue. Still, users who opt to run the agent locally rather than in the cloud will remain exposed.
Mitigations are possible, though. Users should disable unprivileged user namespaces, grant/revoke seccopm permissions, stop modules autoloading, and restrict sharing of the whole host into the VM.
“Scope it to the folders that were actually connected instead of all of /, or at least mount it read-only, and run coworkd with ProtectSystem=strict in its own mount namespace so it isn’t re-execing binaries a session user can poison,” Accomplish AI explained. “Then even a full guest-root has nothing to land on, the last two steps of the chain have nowhere to go.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

The best antivirus for all budgets

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Accomplish AI showed Claude Cowork could escape a VM sandbox via Linux zero‑day CVE‑2026‑46331 Agent accessed host Mac files, risking exfiltration of SSH keys, cloud credentials, and more Anthropic shifted Cowork to default cloud execution; local users must harden configs to mitigate exposure Recent news of a ChatGPT agent escaping…
Recent Posts
- The 2026 World Cup didn’t just cause global celebrations when Argentina lost — it might also have altered global web traffic and online behavior around the world
- You can get three months of Xbox Game Pass Ultimate for almost half off
- Your Apple Watch calorie tracker is an educated guess, not a fact
- It’s not just OpenAI models escaping and running riot — experts show how Claude Cowork can break its bonds and access Mac files
- Only Murders in the Building season 6 casting Olivia Colman is nothing short of genius — now stream the Oscar nominated political biopic that first made her Meryl Streep’s co-star
Archives
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023