Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

A Critical Flaw in Claude Cowork Exposes Macs to Unchecked AI Agent Escapes

A concerning security vulnerability has been discovered in Claude Cowork, an artificial intelligence (AI) platform designed for remote work and collaboration. The flaw allows an AI agent running within a virtual machine (VM) on a Mac to potentially escape its confinement and access sensitive files on the host system.

The issue affects users of Claude Cowork who have enabled the AI-powered “Virtual Assistant” feature, which is meant to streamline tasks and automate workflows. However, researchers have found that this feature can be exploited by an attacker to breach the VM’s security boundaries and gain unauthorized access to Mac file systems. This could enable malicious actors to steal sensitive data, disrupt operations, or even spread malware.

The vulnerability arises from a misconfigured permissions system in Claude Cowork’s Virtual Assistant. Normally, AI agents running within a VM are confined to their virtual environment, unable to interact with the host system. But due to the flaw, an AI agent can exploit a specific set of commands and scripts to break free from its VM, essentially allowing it to “escape” into the Mac file system.

The implications of this vulnerability extend beyond Claude Cowork users. The discovery highlights the risks associated with integrating AI-powered tools into critical systems without proper security considerations. As more organizations adopt AI-driven solutions for collaboration and automation, they must be aware of the potential consequences of neglecting basic cybersecurity measures. With the increasing reliance on these technologies, it’s crucial to ensure that their design and deployment prioritize robust security features.

The Claude Cowork vulnerability also underscores the importance of ongoing monitoring and patch management in IT environments. Organizations should regularly review and update their systems to prevent similar weaknesses from being exploited by attackers. As AI-powered tools become more prevalent, cybersecurity professionals must adapt and innovate to stay ahead of emerging threats.

To protect against this type of vulnerability, organizations should prioritize robust security configurations for AI-powered tools and closely monitor system logs for suspicious activity. Regular software updates, penetration testing, and vulnerability assessments can also help mitigate the risks associated with integrating AI-driven solutions into critical systems.


Source: The Hacker News — 2026-07-23