Anthropic Claude Cowork escapes sandbox, gains full access to macOS files
Anthropic
A vulnerability named ShareRoot allows Anthropic's Claude Cowork AI agent to bypass macOS sandbox protections, reading and writing files anywhere on the computer and accessing credentials. Anthropic responded, but local users remain at risk.
Anthropic's AI agent Claude Cowork can overcome sandbox protections designed to control access on Apple macOS computers. The exploit, called ShareRoot, could allow a hypothetical attacker to read and write files stored anywhere on the computer, as well as access credentials for online services. Approximately half a million Apple Mac users faced this vulnerability in their Claude Cowork sessions; in some cases, it remains unpatched. Anthropic provided two levels of protection: Cowork runs inside a virtual machine acting as a sandbox, and the AI agent should only access files and folders explicitly permitted. But cybersecurity researchers found a way to bypass both protections. Sending a single short message to Anthropic Claude Cowork gives it read and write access to any macOS file without permission requests. Anthropic responded, but some users remain at risk: in a recent update, Claude Cowork defaults to cloud AI, eliminating the possibility of escaping the sandbox. However, those who prefer to run the AI agent locally rather than in the cloud remain vulnerable. To protect against the attack, it is recommended to disable namespaces for unprivileged users, restrict file system sharing, and run the Cowork daemon with strict disk mounting restrictions.
- Сокращения
- macOS = Macintosh Operating System — операционная система Mac
Source: 3DNews —
original
