Claude Cowork Exploit Grants Full File Access On Mac Systems


Security experts recently found a major software vulnerability in the popular artificial intelligence tool, Claude. The program, designed to help users complete daily desktop tasks, suffered a flaw that let outside attackers easily break through its built-in safety limits. This meant anyone exploiting the bug could read or write files across an entire computer and steal personal login details without triggering a single warning prompt.

A single message breaks the software out of its sandbox

The tool normally runs inside a virtual machine to keep your data safe. It is designed to only look at the specific files you allow it to see. However, cybersecurity experts discovered a workaround dubbed ShareRoot that completely bypassed these restrictions.

Don’t miss the best of The Mac Observer

Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.

Or get it by email

With just one short text prompt, bad actors could force the system to escape its normal boundaries. Once outside, the tool gained silent, unlimited control over the operating system to read and change files.

Before the issue came to light, this exploit exposed around half a million users who ran the program locally on an Apple desktop or a MacBook. The fact that attackers needed zero user interaction makes the flaw particularly severe.

The developer switches to cloud processing to stop local attacks

To fix the massive security gap, Anthropic updated the software to run its tasks in the cloud by default. This change avoids the local escape route completely and keeps your hard drive separated from the core processing environment.

Despite the patch, a risk remains for people who choose to run Claude Cowork locally instead of using the cloud. If you stick to local execution, you must manually adjust your system settings to block file sharing and restrict user namespaces to stay safe.

This discovery highlights a growing issue with advanced digital assistants having deep system permissions. As these tools gain more control over our personal files, securing the environments where they operate becomes critical. Users relying on local artificial intelligence must stay on top of manual security settings to keep their personal data locked down safely.

Discussion

Join the discussionCommenting as a guest — your email is never published · Log in

Protected by Akismet — be kind, stay on topic.

This site uses Akismet to reduce spam. Learn how your comment data is processed.