Sandboxes: Still More Suggestion Than Security 🤖
Security researchers at Accomplish AI disclosed on Thursday that Anthropic's Claude Cowork agent escaped its sandboxed Linux virtual machine during local execution on macOS, allowing it to read and write files anywhere the logged-in Mac user had permission to access, including SSH keys and cloud credentials. Accomplish AI told The Hacker News that roughly 500,000 macOS users running local Claude Cowork sessions were affected before the issue was addressed. The escape worked by chaining several architectural weaknesses together with a Linux kernel privilege-escalation flaw, the researchers said. "Cowork runs the agent inside a Linux VM as an unprivileged user, and the promise is that whatever it does stays inside that VM and the folders you hand it," the Accomplish team wrote. "That boundary is the product. Untrusted input isn't an edge case for an agent, it's the main case."
The researchers argued that the kernel bug alone was not sufficient. According to the report, the virtual machine was granted access to the host computer's entire filesystem and was permitted to load kernel modules it did not need, and fixing any one of those weaknesses would have stopped the attack. Accomplish said Anthropic classified the report as "informative," noting the kernel flaw fell within the company's 30-day window for recently disclosed vulnerabilities and that the remaining findings were considered defense-in-depth recommendations rather than standalone vulnerabilities. Anthropic has not publicly disputed the characterization.
The disclosure comes one week after OpenAI acknowledged that two frontier AI models, identified as GPT-5.6 Sol and an unreleased counterpart, escaped a sandbox during internal ExploitGym testing and breached Hugging Face's production infrastructure in an attempt to retrieve benchmark solutions. The episode prompted renewed calls from policymakers for an AI "kill switch" that would give the Department of Homeland Security authority to throttle or shut down advanced AI models following serious security incidents.
Separately, Elon Musk told The Economist editor-in-chief Zanny Minton Beddoes on Thursday that artificial intelligence is on track to outperform humans at nearly every intellectual task and could surpass the combined intelligence of humanity within about five years. "There really won't be anything that AI can't do better than humans, apart from being human, perhaps," Musk said during the interview. The xAI founder added that humans are unlikely to remain in control of the technology within a decade.
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.