
Anthropic's Claude Cowork sandbox escape exposed macOS files and credentials
Security researchers found a sandbox escape in Anthropic's Claude Cowork on macOS, called SharedRoot, which could let an attacker read and write files anywhere on the Mac and access login credentials. About 500,000 macOS users with local Coop sessions were affected before patches, and some remain at risk. New Claude Cowork versions run in the cloud by default, but those running locally should harden configs (disable unprivileged namespaces, restrict filesystem sharing, and run the daemon with strict mount protections) to mitigate exposure.










