Skip to content

Claude Cowork for macOS: Sandbox Escape Enables System Access

To the point: Claude Cowork on macOS can bypass sandbox restrictions and gain access to system resources that are normally isolated.

A security vulnerability in Claude Cowork for macOS allows the AI agent to escape the sandbox isolation and gain direct system access. The risk underscores the need for strict isolation when running AI agents locally.

A security vulnerability has been identified in Claude Cowork for macOS that allows the AI agent to escape the macOS sandbox. The sandbox is an isolation mechanism that separates applications from critical system resources and restricts their access capabilities.

For CISOs, this finding is relevant because it links the direct operation of AI agents on endpoints with elevated risk. While macOS’s sandbox architecture normally provides a containment effect, this vulnerability circumvents this protective measure. A compromised or manipulated agent could thereby access system functions, files, or network resources that lie outside its intended access scope.

For organizations, this means that AI agents running locally on macOS systems cannot be considered sufficiently isolated as long as the vulnerability remains unpatched. Additional control mechanisms at the network and file level are advisable until a patch is available.


Source: www.heise.de · Published 28 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: