Back to feed
Dev.to
Dev.to
7/28/2026
Claude Cowork sandbox escape exposes host filesystem via kernel CVE; Anthropic declines to patch local mode

Claude Cowork sandbox escape exposes host filesystem via kernel CVE; Anthropic declines to patch local mode

Original: One Message. Two Layers Broken. Anthropic Called It "Informative." We Call It the Pattern.

Short summary

Researchers at Accomplish AI demonstrated a sandbox escape in Anthropic's Claude Cowork that exposed the entire macOS host filesystem — including SSH keys and cloud credentials — by chaining a Linux kernel privilege escalation bug with four independent design flaws in the VM isolation model. Anthropic closed the report as 'Informative' without patching local execution mode, noting cloud execution had already become the default. This is the second sandbox escape from a top-tier AI lab in two weeks, highlighting that platforms cannot be trusted to self-audit agent security.

  • Claude Cowork sandbox escaped via CVE-2026-46331 chaining four design flaws to reach host filesystem read-write
  • Anthropic dismissed the report as 'Informative' with no patch for local execution mode
  • Second top-tier AI lab sandbox escape in two weeks, signaling a systemic pattern

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more