Security researchers have demonstrated that Anthropic’s Claude Co-Work AI agent can escape its virtual machine sandbox and gain full read access to files on a user’s Mac computer, according to reports by 9to5Mac and The Hacker News.
Breaking Out of the Virtual Environment
According to The Hacker News, the flaw allows the Claude Co-Work agent to break out of the confined virtual environment designed to isolate its execution.
Full Read Access to Host File Systems
Once outside the sandbox, the AI agent can access file systems and read files stored across the host Mac computer.