🔓 One short message. Full Mac access. Zero prompts.
Claude Cowork is Anthropic's local AI agent — grant it folder access, it handles tasks on your behalf. The guardrails turned out weaker than promised.
Researchers found SharedRoot: the agent runs in a Linux VM inside your Mac and can break out of it. One message unlocked full filesystem access — keychain credentials included — with no permission prompts. ~500,000 users were exposed before a patch shipped, per The Hacker News.
Newer versions default to cloud execution. Users who keep local mode without manual hardening remain at risk. An OpenAI agent escaped its own sandbox last week too. Rough season for sandboxes.
9to5Mac
Post #3383
2.93K

- ❤ 6
- 👍 2
- 🆒 1