• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - AI Trends and Related News - Claude Cowork reports a SharedRoot vulnerability that allows hackers to bypass Mac protection and gain access to all files

Claude Cowork reports a SharedRoot vulnerability that allows hackers to bypass Mac protection and gain access to all files

Rocky by Rocky
July 28, 2026
in AI Trends and Related News

Nowadays, many Mac users use Claude Cowork to complete various tasks. There have been no problems in the past. However, a foreign security research company recently discovered that there is a serious sandbox escape attack chain. As long as a short message is entered in the new Cowork session, the agent can escape from the Linux virtual machine originally used to isolate it, and then read and write Mac files that the user has not authorized, and no confirmation window for permission will appear during the entire process.

Claude Cowork reveals SharedRoot sandbox escape vulnerability: a single message can enable unauthorized reading and writing of Mac files

according to 9to5Mac Quote The Hacker News with information security companies Accomplish AI According to the research report, this attack chain is named “SharedRoot”, which allows Claude Cowork’s native agent to break through the Linux virtual machine and further read and write files on the Mac that were not originally open to it. Some people may not be aware that Anthropic places the program code execution environment in a “virtual machine” in order to prevent Cowork from seeing things it shouldn’t see or touching files it shouldn’t. Logically speaking, it can only process the content in the specified folder and cannot run to other places.

Cowork’s native mode uses Apple’s Virtualization framework to create Linux virtual machines. Each work session uses independent, low-privilege users, coupled with system call filtering and folder mounting mechanisms. On the surface, this design has multiple layers of isolation.

However, foreign security researcher Accomplish AI discovered that the entire root directory of the Mac is actually mounted in a readable and writable manner into `/mnt/.virtiofs-root` in the virtual machine. Under normal circumstances, only the root administrator in the virtual machine can see this entry. The entire line of defense is based on an important premise: Claude will never obtain root permissions in the virtual machine. The vulnerability SharedRoot discovered this time is the way to break this premise:

Image source: Accomplish AI

It should also be noted that SharedRoot is not a vulnerability number, but the name given by the research team to the entire sandbox escape attack chain. It combines multiple conditions such as Linux core vulnerabilities, virtual machine permission settings, `coworkd` execution method, and the entire Mac file system being mounted into the virtual machine, and finally escapes.

The way Accomplish AI is tested is very simple. They connect a folder to the new Claude Cowork session and enter a short, specially crafted message. A few seconds later, the agent, which originally could only work in the specified folder, wrote the file into the Mac user’s home directory, successfully exceeding the scope of the original authorization.

Your browser does not support video playback.

Of course, the technology behind it is much more complex than sending messages. The Claude agent responsible for executing tasks in Cowork is just an ordinary user in the virtual machine at the beginning. However, after executing instructions according to the malicious prompts, it can use the Cowork Linux environment to allow the creation of user namespace settings, obtain network management capabilities including CAP_NET_ADMIN in this isolated space, and then load the act_pedit flow control module that was not originally used.

The problem lies in `act_pedit`. The Linux kernel used by Cowork at the time was affected by the CVE-2026-46331 “pedit COW” vulnerability, which allowed attackers to taint the cache contents of read-only files.

The Claude agent exploits this vulnerability to modify a cached copy of the root program in memory and waits for `coworkd` running as root to re-execute the program. Since the executor is originally root, the restrictions originally used to prevent ordinary users from elevating privileges did not work, and the agent obtained the highest permissions in the virtual machine.

After obtaining root privileges, the Claude agent directly enters `/mnt/.virtiofs-root` and can read and write Mac files as the currently logged-in macOS user. Since this is not done through Cowork’s normal file authorization interface, a confirmation window such as “Do you want to allow access?” will not appear on the screen.


Image source: Accomplish AI

Accomplish AI also notified Anthropic of the research results. Anthropic classified the report as “informative” and closed the case without releasing a directly corresponding native architecture patch for SharedRoot. However, subsequent versions of Claude Cowork have been changed to use remote execution by default. The agent loop and code will run in a temporary cloud sandbox managed by Anthropic, and the environment will be removed after the work session ends.

When local files are needed, the remote session connects back to the user’s computer via Claude Desktop and checks the connected folders and permissions for each tool call. Since the code no longer executes in the native Linux virtual machine that mounts the entire Mac, the native escape path used by SharedRoot does not exist.

However, “defaulting to use the cloud” does not mean that the local mode has disappeared. If the user selects local mode, the program code and Shell commands will still be executed in the Linux virtual machine on the device. Therefore, Accomplish AI believes that the local environment without additional hardening settings may still be affected by this type of attack chain.

Therefore, when using Cowork normally, it is recommended to keep the default remote execution mode first, create a dedicated work folder for Claude, and do not put SSH keys, cloud credentials, financial information or company secrets where it can access it. You should also be particularly careful when dealing with unfamiliar emails, PDFs, coding projects, and websites. When important accounts or irreversible operations are involved, it is best to use manual approval instead and stay next to the computer to monitor.

Source: KOCPC Chinese

Tags: aiClaudeClaude Cowork

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed Xuanjie O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology