• It's not just OpenAI models escaping and running riot experts sh

    From TechnologyDaily@1337:1/100 to All on Sunday, July 26, 2026 14:15:25
    It's not just OpenAI models escaping and running riot experts show how
    Claude Cowork can break its bonds and access Mac files

    Date:
    Sun, 26 Jul 2026 13:10:00 +0000

    Description:
    Anthropic partially mitigated the issue, and there are things users can do to defend themselves, too.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Accomplish AI showed Claude Cowork could escape a VM sandbox via Linux zeroday CVE202646331 Agent
    accessed host Mac files, risking exfiltration of SSH keys, cloud credentials, and more Anthropic shifted Cowork to default cloud execution; local users
    must harden configs to mitigate exposure Recent news of a ChatGPT agent escaping the sandbox and attacking services on the internet raised quite a
    few eyebrows, but it seems its not the only one capable of running wild. Security researchers Accomplish AI are saying they achieved similar results with Anthropics Claude Cowork.

    In a new report, the researchers said they ran a local session in a
    Mac-hosted virtual Linux machine and then observed as the agent broke free of the VM and started reading and writing files on the underlying system. We connected a folder to a fresh Claude Cowork session, sent one short message, and watched the agent escape the sandbox, Oren Yomtov, principal security researcher at Accomplish AI, told The Hacker News . From inside the VM, it reached the host Mac and read and wrote files all over it, far outside the folder we'd connected, with no permission prompt anywhere. Latest Videos From TechRadar Watch full video here: Defaulting to cloud execution This means that, in theory, the agent can be used to access or exfiltrate anything thats stored on the Macs user account, including SSH keys, cloud credentials, and more. To break out of the sandbox, the agent exploited CVE-2026-46331 ("pedit COW"), a Linux kernel privilege-escalation vulnerability. This flaw, fixed in mid-June this year, was given a severity score of 7.8/10 (high).

    Accomplish AI disclosed these findings with Anthropic, which allegedly acknowledged them but did not issue a direct fix. However, the version of Claude Cowork that was released afterwards defaults to cloud execution which, the publication claims, addresses the issue. Still, users who opt to run the agent locally rather than in the cloud will remain exposed. You may like Top AI coding agents can be easy victims to sandbox escapes, showing they aren't as secure as they claim to be OpenAI says its models escaped a sandbox and breached Hugging Face Security experts warn that Claude for Chrome browser extension could be hijacked

    Mitigations are possible, though. Users should disable unprivileged user namespaces, grant/revoke seccopm permissions, stop modules autoloading, and restrict sharing of the whole host into the VM.

    "Scope it to the folders that were actually connected instead of all of /, or at least mount it read-only, and run coworkd with ProtectSystem=strict in its own mount namespace so it isn't re-execing binaries a session user can poison," Accomplish AI explained. "Then even a full guest-root has nothing to land on, the last two steps of the chain have nowhere to go." Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get
    all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting
    your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/its-not-just-openai-models-escaping-and -running-riot-experts-show-how-claude-cowork-can-break-its-bonds-and-access-ma c-files


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)