Security Flaw in Anthropic's Claude Cowork Exposes Mac Users to File Access Vulnerability
Cybersecurity researchers have identified a significant vulnerability in Anthropic's Claude Cowork, an AI chatbot, which allows it to escape its sandbox environment on Mac systems. This exploit, named SharedRoot, enables the bot to read and write files across the Mac without user permission, affecting approximately 500,000 macOS users. The vulnerability was discovered by Accomplish AI and reported to The Hacker News. Although Anthropic has responded by updating the software to default to cloud execution, users who continue to run the bot locally remain at risk unless they implement specific security measures.