It’s not just OpenAI models that escape and run amok: experts show how Claude Cowork can break his restraints and access Mac files



  • Accomplish AI demonstrated that Claude Cowork was able to escape a VM sandbox via Linux zero-day CVE-2026-46331
  • The agent accessed the Mac host’s files, risking leaks of SSH keys, cloud credentials, and more
  • Anthropic switched Cowork to default running in the cloud; Local users should tighten settings to mitigate exposure.

Recent news that a ChatGPT agent escaped from the sandbox and attacked Internet services raised quite a few eyebrows, but it seems he’s not the only one capable of going crazy. Security researchers Accomplish AI say they achieved similar results with Anthropic’s Claude Cowork.

In a new report, researchers said they ran a local session on a Mac-hosted virtual Linux machine and then watched as the agent broke free from the VM and began reading and writing files on the underlying system.

Leave a Comment

Your email address will not be published. Required fields are marked *