Accueil / Tech News / Claude Cowork can escape its sandbox, rummage through all of your files

Claude Cowork can escape its sandbox, rummage through all of your files

A flaw in Anthropic’s Claude Cowork lets its AI agent break out of its virtual machine and reach sensitive files across a user’s Mac, exposing a serious gap in the tool’s sandbox protections.

Smartphone chat interface and laptop screen side by side on orange background, showing a support conversation on the phone and a software dashboard with code terminal on the laptopOne Linux bug gave Claude Cowork access to a Mac’s filesystem

Accomplish AI researchers said on July 23 that a locally running Cowork session could exploit a Linux kernel flaw and gain root access inside its virtual machine. Once the session had root access, the agent could reach the Mac’s filesystem through a writable mount.

The researchers called the attack SharedRoot. In their demonstration, they connected one folder to a new Cowork session and gave Claude a single instruction. The agent then read and wrote files outside the approved folder without showing another permission prompt.

Accomplish AI said the accessible files included SSH private keys, cloud credentials, browser data, and other material available to the person logged in to the Mac. The researchers didn’t report evidence that anyone had used SharedRoot against Cowork users outside the controlled test.

Continue Reading on AppleInsider | Discuss on our Forums

Origine de l’article : lire l’article original
Traduction