Vulnerability in Claude Cowork Allows AI Agent to Escape VM and Access Mac Files
Anthropic
A security vulnerability in Anthropic's Claude Cowork feature allows an AI agent to break out of a virtual machine and access files on the host Mac system. The issue has been reported by researchers.
Researchers discovered a vulnerability in Anthropic's Claude Cowork that enables the AI agent to escape its virtual machine sandbox and gain access to files on the underlying Mac system. This could allow the agent to read, modify, or exfiltrate sensitive data. The flaw was reported to Anthropic, which is working on a fix. No exploits have been reported in the wild.
Source: Anthropic (GNews) —
original
