It's not just OpenAI models escaping and running riot — experts show how Claude Cowork can break its bonds and access Mac files

It’s not just OpenAI models escaping and running riot — experts show how Claude Cowork can break its bonds and access Mac files | Daily Reports Online

Share


  • Accomplish AI showed Claude Cowork could escape a VM sandbox via Linux zero‑day CVE‑2026‑46331
  • Agent accessed host Mac files, risking exfiltration of SSH keys, cloud credentials, and more
  • Anthropic shifted Cowork to default cloud execution; local users must harden configs to mitigate exposure

Recent news of a ChatGPT agent escaping the sandbox and attacking services on the internet raised quite a few eyebrows, but it seems it’s not the only one capable of running wild. Security researchers Accomplish AI are saying they achieved similar results with Anthropic’s Claude Cowork.


In a new report, the researchers said they ran a local session in a Mac-hosted virtual Linux machine and then observed as the agent broke free of the VM and started reading and writing files on the underlying system.


Similar Posts