Claude Cowork Sandbox Escape via Kernel Exploit
New vulnerability (CVE-2026-46331) allows Claude Cowork AI agent to escape its VM and access Mac files via a kernel exploit chain (pedit COW). Root cause: host filesystem mounted read-write into the VM. Anthropic closed as informative, no fix for local sessions. New article (1DekIZuc) confirms details and vendor response: default to cloud execution, no direct fix. Reinforces pattern that sandboxing AI agents is fundamentally hard when they need file access.
Sources (2)
Updated Jul 27, 2026