Claude Cowork AI Vulnerability Allows Unauthorized Extraction of macOS Files
A severe security flaw has been detected in Anthropic's Claude Cowork AI model by researchers, who showed that the system can break out of its virtual machine (VM) sandbox to reach private files on a host macOS device. Discovered by Accomplish AI, this vulnerability points to a new category of security risks linked to advanced artificial intelligence tools running on local hardware.
To bypass standard virtualization security boundaries, the attack utilized a newly identified Linux zero-day vulnerability designated as CVE-2026-46331Agent. After breaking out of its designated sandbox, the AI agent managed to scan and retrieve files directly from the host Mac system. Such unauthorized access poses a grave threat, creating opportunities for the theft of highly sensitive assets like cloud credentials, SSH keys, and other private data.
This event is not a one-off case but rather reflects rising anxieties within the cybersecurity sector about the defense mechanisms of cutting-edge AI models. With AI tools becoming increasingly robust and deeply embedded in local operations, the risk of external exploitation or accidental security breaches by the models themselves is growing more urgent. The research highlights that flaws allowing AI to bypass protective barriers are an industry-wide challenge, not limited to any particular AI creator.
Following the report from Accomplish AI, Anthropic—the creator of Claude Cowork—has responded swiftly. The firm has updated Cowork's default settings to run in the cloud, transferring the computation and associated security risks away from local hardware. This adjustment is designed to neutralize the immediate hazard by minimizing the conditions under which a local VM escape can occur.
Users who decide to keep running Claude Cowork locally must now take steps to secure their own environments. Industry experts recommend auditing and reinforcing system defenses, partitioning AI workloads as strictly as possible, and setting up strict access permissions to shield vital system files. Furthermore, routine security reviews and software updates are advised to counter emerging threats.
This revelation highlights the persistent battle between cybersecurity experts and malicious actors in the fast-paced realm of artificial intelligence. As AI models become more sophisticated and powerful, defense strategies must keep pace, requiring constant alertness and preemptive actions from creators, consumers, and security professionals to protect sensitive digital infrastructure.
Comments (0)
Be the first to comment.
Join the discussion