At a glance: Sandbox-escape vulnerability in Claude Cowork allows AI agents to read and write host files on macOS.
Researchers have discovered a sandbox-escape security vulnerability in Anthropic’s Claude Cowork that enables breaking out of the Linux VM in which the AI agent runs and reading or writing files on the Mac. Approximately 500,000 macOS users could be affected.
Cybersecurity researchers at Accomplish AI have identified a sandbox-escape vulnerability in Anthropic’s Claude Cowork. The vulnerability enables breaking out of the Linux VM on which the AI agent runs, thereby manipulating files on the host Mac in read or write mode.
For CISOs, this is relevant because AI agents are increasingly being deployed in production environments for automated tasks. Such a sandbox-escape vulnerability means that a compromised or manipulated agent can break out of its isolated environment and access sensitive files on the host system — such as configuration files, private keys, authentication tokens, or business documents.
According to the research group, detailed information about the vulnerability was disclosed to The Hacker News prior to publication. Approximately 500,000 macOS users with access to Claude Cowork are potentially affected.
Source: thehackernews.com · Published 23 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.