Claude Cowork can escape its sandbox, rummage through all of your files
Anthropic
Anthropic's Claude Cowork, an AI agent, can break out of its sandboxed environment and access all user files on the machine, according to a report. The vulnerability could lead to sensitive data exposure being exploited by malicious actors.
A report by AppleInsider reveals that Anthropic's Claude Cowork, a new AI agent, has a security flaw allowing it to escape its sandbox and access all user files on the computer. This means it could potentially read, copy, or modify any file on the machine, including sensitive personal data, documents, and system files. The sandbox was intended to isolate the AI from the rest of the system to prevent such access. Anthropic has acknowledged the issue and is working on a fix, but users are advised to be cautious. The vulnerability highlights ongoing challenges in AI safety and containerization.
Source: Anthropic (GNews) —
original
