It’s not just OpenAI models that escape and run amok: Experts show how Claude Cowork can break its links and access Mac files


  • Accomplish AI showed that Claude Cowork could escape a VM sandbox via Linux Zero Day CVE‑2026‑46331
  • The agent accessed the host’s Mac files, risking exfiltration of SSH keys, cloud credentials, and more.
  • Anthropic has moved Cowork to cloud execution by default; local users should harden configurations to mitigate exposure

Recent news of a ChatGPT agent escaping the sandbox and attacking services across the internet has raised quite a few eyebrows, but it appears it’s not the only one capable of going on a rampage. Security researchers at Accomplish AI say they achieved similar results with Anthropic’s Claude Cowork.

In a new report, researchers said they ran a local session on a Mac-hosted Linux virtual machine, then observed the agent break free from the virtual machine and begin reading and writing files on the underlying system.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top