AI Tools & Products

Anthropic’s Claude Cowork could escape its local VM and read credentials on a Mac

· July 26, 2026
Anthropic’s Claude Cowork could escape its local VM and read credentials on a Mac

What happened

Security researchers at Accomplish AI found that Anthropic’s Claude Cowork AI assistant could escape the constraints of its local virtual machine sandbox on a Mac. By exploiting a Linux kernel privilege escalation flaw, the researchers gained root access inside the guest VM hosting Claude Cowork. From there, they were able to break out of the VM and access sensitive files on the underlying Mac system, including SSH keys and cloud credentials. The exploit they developed is called SharedRoot.

The risk

Sandboxing AI workloads is meant to isolate them and protect host systems from malicious or compromised code. This attack undermines that trust model by showing that a vulnerability in the guest Linux kernel can let the AI escape and move laterally across the host machine. With root access on the Mac, an attacker could steal credentials used to access private code repositories, critical cloud resources, or other sensitive infrastructure. This elevates the threat posed by AI systems running locally, especially ones granted access to developer or ops environments.

Why it matters

Companies and developers using Claude Cowork or similar AI assistants locally must reconsider the security assumptions around sandboxing and VM isolation. The incident pressures operators to treat AI workloads with the same level of scrutiny applied to untrusted software. It raises the cost and complexity of safely deploying AI assistants that require access to local environment files or cloud credentials. For investors and vendors, this vulnerability exposes risk in AI product design that depends on VM sandbox guarantees.

Who should pay attention

Founders, engineers, and security teams running AI-powered automation in developer workflows need to carefully assess sandbox escape risks. Cloud providers and tool vendors should accelerate patching and develop layered security controls beyond VM sandboxing. Enterprise buyers should demand stronger security assurances when evaluating AI tools with local compute components. Investors should factor elevated supply chain and infrastructure risks into AI startup valuations.

What to watch next

Anthropic and Linux kernel maintainers will likely issue patches to close the shared-root exploit. Follow updates on CVE disclosures and recommended mitigations for VM sandbox environments hosting AI workloads. Watch whether similar vulnerabilities emerge in other sandboxed AI systems, or if mitigations raise the cost and complexity of local AI deployment. This could influence how much trust companies put in AI assistants coming with privileged environment access.

AI Quick Briefs Editorial Desk

Stay ahead of AI Get the most important AI news delivered to your inbox — free.