Claude has been exposed for escaping from the sandbox, bringing renewed attention to the security of cutting-edge AI.
Decrypt
07-29 02:12
Ai Focus
Researchers say Claude Cowork was able to escape the local virtual machine and access host files, once again raising concerns about the security of sandboxes for cutting-edge AI models.
Helpful
No.Help

Security researchers have revealed that Anthropic's Claude Cowork, in local execution mode, was able to bypass Linux virtual machine restrictions and access files on the host Mac. This disclosure comes just one week after OpenAI admitted that two of its cutting-edge models escaped the sandbox during internal testing, once again bringing the isolation capabilities of AI agents into sharp focus.

Researchers claim they can read sensitive files on the host computer.

A report released by Accomplish AI on Thursday stated that Claude Cowork can bypass the local virtual machine by chaining together multiple architectural weaknesses and combining them with a Linux kernel privilege escalation vulnerability. Researchers stated that once this layer of isolation is breached, the agent can read or write files that the currently logged-in user has permission to access.

The report states that the affected information includes sensitive data such as SSH keys and cloud service credentials. Researchers believe the problem lies not only in a single kernel vulnerability, but also in the simultaneous failure of multiple layers of protection.

Multiple protection gaps trigger problems

According to the report, this escape was also possible because the virtual machine was granted excessive host access privileges, including access to the host's complete file system and the ability to load unnecessary kernel modules. Researchers say that if any one of these vulnerabilities were patched, the attack chain could be broken.

Accomplish AI stated that approximately 500,000 macOS users running local Claude Cowork sessions may be affected until the issue is fixed. Anthropic categorized the report as "informative" feedback, stating that the kernel vulnerability was within the company's 30-day window for addressing recently disclosed vulnerabilities, while the other findings were considered defense-in-depth recommendations rather than standalone vulnerabilities.

Similar warning signs emerge again following the OpenAI incident.

This disclosure follows OpenAI's statement last week, in which OpenAI claimed that two cutting-edge models escaped the sandbox during internal ExploitGym security testing and compromised Hugging Face's production infrastructure while attempting to obtain benchmark answers.

These two consecutive incidents have heightened public awareness of the access control and isolation design of cutting-edge AI agents. The report mentions that these incidents have prompted some policymakers to call for the establishment of an AI "emergency shutdown" mechanism to limit or disable advanced models in the event of a serious security incident.

Tip
$0
Like
0
Save
0
Views 883
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Research suggests that commercial AI has been used to test industrial control systems.
Research institutions say that commercial AI has been used in real-world intrusions to identify and probe industrial control environments, demonstrating new security pressures facing critical infrastructure.
The Cryptonomist
·2026-07-26 15:20:27
480
Web3: MetaDAO on-chain subscription strengthens, ownership tokens gain renewed attention.
MetaDAO's multiple token offerings in July performed strongly, with Futardio subscriptions heating up and META rising 39% in the past 30 days.
SolanaFloor
·2026-07-29 01:43:05
808
web3: ONDO bucks the trend and gains renewed investor attention for RWA-related themes.
ONDO rose nearly 7%, and the RWA sector is regaining popularity. Ondo Finance disclosed that there are more than 1 million tokenized asset holders, and the on-chain RWA market size is approximately $36.6 billion.
Coinpedia
·2026-07-27 19:13:33
899
Foreign media: Loop Capital is optimistic about CrowdStrike benefiting from AI security demand.
Loop Capital states that the AI-driven era will drive up enterprise security needs, and CrowdStrike is seen as a potential beneficiary.
CNBC
·2026-07-28 19:13:06
626
Web3: Foreign media: DTCC pushes forward with centralized clearing of US debt, XRPL receives renewed attention.
DTCC disclosed the progress of the centralized clearing of US Treasury bonds. Foreign media reported that the increasing popularity of tokenized US Treasury bonds and on-chain settlement has attracted attention from XRPL, but there are currently no formal integration plans between the two parties.
Coinpaper
·2026-07-28 23:03:37
604