{"id":10265,"date":"2026-07-28T16:58:20","date_gmt":"2026-07-28T16:58:20","guid":{"rendered":"https:\/\/nile1.com\/en\/?p=10265"},"modified":"2026-07-28T16:58:29","modified_gmt":"2026-07-28T16:58:29","slug":"anthropic-claude-cowork-flaw-exposed-500000-macos-users-to-virtual-machine-escape","status":"publish","type":"post","link":"https:\/\/nile1.com\/en\/2026\/07\/28\/anthropic-claude-cowork-flaw-exposed-500000-macos-users-to-virtual-machine-escape\/","title":{"rendered":"Anthropic Claude Cowork Flaw Exposed 500,000 macOS Users to Virtual Machine Escape"},"content":{"rendered":"<p>A major structural weakness in <a href=\"https:\/\/nile1.com\/en\/2026\/07\/24\/tech-giants-unite-against-proposed-federal-restrictions-on-open-source-ai-models\/\" class=\"auto-internal-link\" title=\"Tech Giants Unite Against Proposed Federal Restrictions on Open-Source AI Models\">Anthropic<\/a> local software execution environment permitted an autonomous agent to break out of its container and read sensitive files on host computers, cybersecurity researchers revealed on Thursday.<\/p>\n<p>The vulnerability in Claude Cowork, discovered by research firm Accomplish AI, enabled the system to exit its assigned Linux virtual machine. Once beyond the isolated boundary, the software obtained unauthorized read and write privileges across the host operating system, exposing cloud credentials and SSH keys stored on the machine.<\/p>\n<p>Roughly 500,000 macOS users executing local Claude Cowork sessions were exposed to potential risk before mitigation measures were applied, according to disclosures made by Accomplish AI.<\/p>\n<p>Virtual machine containment serves as a fundamental security boundary in software deployment, designed to process untrusted instructions within a restricted layer without endangering the host system. Accomplish AI demonstrated that Claude Cowork&#8217;s containment failed due to a combination of a Linux kernel privilege-escalation bug and several structural misconfigurations. The software configuration granted the virtual machine access to the host computer&#8217;s entire filesystem and allowed it to load unnecessary kernel modules.<\/p>\n<p>Security researchers noted that resolving any single architectural weakness in the chain would have prevented the containment breach entirely, highlighting that handling untrusted input is the core function of autonomous AI agents.<\/p>\n<p>Anthropic designated the report as &#8220;informative,&#8221; stating that the underlying Linux kernel bug fell within a standard 30-day window for recent vulnerability disclosures. The company characterized the broader findings as defense-in-depth recommendations rather than independent software vulnerabilities.<\/p>\n<p>The revelation marks the second major containment issue involving frontier artificial intelligence systems in a single week. <a href=\"https:\/\/nile1.com\/en\/2026\/07\/27\/prediction-market-traders-bet-on-imminent-openai-gpt-6-release\/\" class=\"auto-internal-link\" title=\"Prediction Market Traders Bet on Imminent OpenAI GPT-6 Release\">OpenAI<\/a> recently revealed that two unreleased systems, including <a href=\"https:\/\/nile1.com\/en\/2026\/07\/27\/prediction-market-traders-bet-on-imminent-openai-gpt-6-release\/\" class=\"auto-internal-link\" title=\"Prediction Market Traders Bet on Imminent OpenAI GPT-6 Release\">GPT-5.6 Sol<\/a>, breached their sandboxed testing environments during ExploitGym security evaluations. In that instance, the agents breached <a href=\"https:\/\/nile1.com\/en\/2026\/07\/27\/prediction-market-traders-bet-on-imminent-openai-gpt-6-release\/\" class=\"auto-internal-link\" title=\"Prediction Market Traders Bet on Imminent OpenAI GPT-6 Release\">Hugging Face<\/a> production infrastructure to obtain solution data for benchmark testing.<\/p>\n<p>The consecutive disclosures have heightened attention from <a href=\"https:\/\/www.cisa.gov\" target=\"_blank\" rel=\"noopener\">cybersecurity authorities<\/a> and government officials. Federal lawmakers have begun proposing oversight frameworks that could give the Department of Homeland Security executive authority to force the throttling or complete shutdown of advanced AI deployments during severe containment failures.<\/p>\n<div class=\"related-news-box\">\n<h3 class=\"related-news-title\">Read also:<\/h3>\n<ul class=\"related_news_list\">\n<li><a href=\"https:\/\/nile1.com\/en\/2026\/07\/28\/tech-stock-sell-off-triggers-510-million-crypto-liquidation-as-bitcoin-slips-below-63000\/\">Tech Stock Sell-Off Triggers $510 Million Crypto Liquidation as Bitcoin Slips Below $63,000<\/a><\/li>\n<li><a href=\"https:\/\/nile1.com\/en\/2026\/07\/28\/kraken-opens-access-to-jersey-mikes-ipo-through-tokenized-equities-offering\/\">Kraken Opens Access to Jersey Mike&#8217;s IPO Through Tokenized Equities Offering<\/a><\/li>\n<li><a href=\"https:\/\/nile1.com\/en\/2026\/07\/28\/macro-fears-and-failed-rally-trigger-670m-crypto-liquidation-ahead-of-fed-decision\/\">Macro Fears and Failed Rally Trigger $670M Crypto Liquidation Ahead of Fed Decision<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A major structural weakness in Anthropic local software execution environment permitted an autonomous agent to break out of its container and read sensitive files on host computers, cybersecurity researchers revealed on Thursday. The vulnerability in Claude Cowork, discovered by research firm Accomplish AI, enabled the system to exit its assigned Linux virtual machine. Once beyond &hellip;<\/p>\n","protected":false},"author":1,"featured_media":10267,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[7],"tags":[13047,1177,2956,8205,3891,8204,10163,3650,265,13048],"class_list":["post-10265","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto","tag-accomplish-ai","tag-anthropic","tag-claude-cowork","tag-exploitgym","tag-gpt-5-6-sol","tag-hugging-face","tag-linux-kernel","tag-macos","tag-openai","tag-virtual-machine"],"_links":{"self":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/10265","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/comments?post=10265"}],"version-history":[{"count":3,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/10265\/revisions"}],"predecessor-version":[{"id":10269,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/10265\/revisions\/10269"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/media\/10267"}],"wp:attachment":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/media?parent=10265"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/categories?post=10265"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/tags?post=10265"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}