Claude Cowork AI app leaks Mac files
Anthropic's Claude Cowork can run code for you inside a separate Linux system on your Mac. Researchers found a bug chain that lets an attacker who already has code running in that separate system break out and read or change files on the real Mac, including credentials and private data.
- Report priority
- High
- Targets
- Claude Cowork+3 more
How it works
An attacker with code already running inside Cowork's Linux virtual machine can trigger a bug in the Linux kernel's network traffic-control code that skips a safety copy step, letting that code write into memory shared with the host Mac and break out of the virtual machine.
What to do
If you use Claude Cowork's local execution mode on macOS, and the public advisory does not name an exact affected or fixed Cowork build or kernel version to compare against yet, watch Anthropic's own advisory and the Claude app's update channel for a fix, and until then avoid running untrusted tasks or files through Cowork's local execution mode.
Technical details
Affected software: Claude Cowork, Anthropic, macOS, Linux kernel
The chain researchers named SharedRoot combines Claude Cowork's local execution mode, which runs tasks inside a Linux virtual machine sharing files with the host Mac, with CVE-2026-46331 in the Linux kernel's act_pedit traffic-control code. The kernel calculates a copy-on-write range before it knows the full region a write will touch, so under certain conditions a write can land directly in shared page-cache data instead of a private copy. Combined with Cowork's host-filesystem sharing design, code already running inside the VM can use that miscalculation to reach data outside the VM, exposing or modifying files the logged-in macOS user can access, including credentials.
References
- support.claude.com · 14479288-claude-cowork-architecture-overview SOCRadar
- ubuntu.com · CVE-2026-46331 SOCRadar
- accomplish.ai · sharedroot-escaping-claude-cowork-sandbox SOCRadar
- github.com · main SOCRadar
- bleepingcomputer.com · new-dolphin-x-malware-uses-ai-to-rank-high-value-targets BleepingComputer
- zerodayinitiative.com · ZDI-26-451 Zero Day Initiative
- wid.cert-bund.de · securityadvisory CERT-Bund Advisories
- acn.gov.it · rilevata-vulnerabilita-in-prodotti-eset-1 ACN CSIRT Italy
- acn.gov.it · rilevate-vulnerabilita-in-freepbx ACN CSIRT Italy
- acn.gov.it · vulnerabilita-in-prodotti-schneider-electric-13 ACN CSIRT Italy
- neuracybintel.com · kddi-data-breach-exposes-email-addresses-and-passwords-of-over-12-million-users-across-japanese-isps NeuraCybIntel
- neuracybintel.com · carvalima-transportes-hit-by-incransom-cyber-attack-brazilian-logistics-firm-faces-data-breach NeuraCybIntel
- openwall.com · 1 Openwall oss-security
- securityweek.com · upbound-group-says-data-breach-led-to-13-million-in-fraudulent-contract-losses SecurityWeek