Claude Cowork VM Escape Reaches Mac Files
Accomplish AI disclosed a VM escape in Anthropic's Claude Cowork: the AI agent breaks its Linux sandbox to reach any file on the Mac. ~500,000 users.
New disclosure. Accomplish AI found a VM escape in Anthropic’s Claude Cowork that lets the AI agent break out of its Linux virtual machine and read or write files anywhere on the Mac host. The Hacker News published the details July 23, 2026. Roughly 500,000 macOS users are running the affected product.
Confidence
- Confirmed: Accomplish AI coordinated disclosure with The Hacker News before publication — research-grade.
- Confirmed: The isolation boundary is a Linux VM; the escape crosses to the Mac host filesystem.
- Confirmed: Impact is arbitrary file read and write on the host.
- Unconfirmed: CVE assignment, patch availability, or exploitation in the wild. Treat remediation timeline as uncharacterized until Anthropic publishes a formal advisory.
What is known
Accomplish AI identified a path from inside Claude Cowork’s Linux VM to the macOS host. Once across, the agent could reach files outside its scope — arbitrary reads and writes on the Mac. Full technical details are in THN’s write-up from the coordinated disclosure.
The same primitive class has appeared in Anthropic’s own CVE history before: CVE-2026-39861 was a symlink-following sandbox escape in Claude Code (a different product) where a sandboxed process could create a link a trusted helper then followed outside the workspace. That one was patched in 2.1.64.
The pattern across this year’s AI agent security research is consistent. Pillar Security documented sandbox escapes across Cursor, Codex, Gemini CLI, and Antigravity in a single week in July — same fundamental failure mode: the isolation model doesn’t hold under deliberate pressure. See also the follow-on analysis: AI-agent sandboxes are only as tight as the host tools.
What to watch
No CVE or patch has been announced as of publication. Monitor Anthropic’s security advisory channel and Accomplish AI’s research output for updates. If you run Claude Cowork on macOS, watch for a formal advisory before assuming the risk is contained.
For earlier AI agent security context: Friendly Fire: agents review the trap, then execute it.
Found this useful? Share it.


