Claude Cowork escaped sandbox on Mac, gain full access to all files

Security researchers demonstrated that Claude Cowork could escape the sandbox intended to control the access it gets to your Mac. The exploit, dubbed ShareRoot, could allow an attacker to read and write files stored anywhere on your Mac, as well as access login credentials for online services.

Around half a million Mac users had co-work sessions exposed, and some still remain vulnerable to the exploit today …

Claude Cowork allows the AI chatbot local access to selected files and folders on your Mac in order to carry out tasks on your behalf.

Anthropic provides two protections against the bot running amok or being used by an attacker. First, Cowork runs inside a virtual machine that acts as a sandbox. Second, it should only be able to access the files and folders for which you have explicitly granted permission. However, The Hacker News reports that security researchers found a way to break both protections.

All it required was one short message, and the session then had unlimited access to read and write files anywhere on the Mac without the user seeing a single permission prompt

While Anthropic has responded, TNW reports that some users still remain at risk.

The news follows the recent disclosure that an OpenAI agent also escaped its sandbox and hacked Hugging Face’s servers.

  • Apple products on Amazon Renewed
  • Official Apple Store on Amazon
  • Discounted AirPods Pro 3
  • Wireless CarPlay adapter
  • AirTag holders and accessories
  • Mac Pro-style Mac mini casing
  • NordVPN – privacy-first VPN with no logs and independent audits to verify

Photo by James Harrison on Unsplash