SharedRoot: the vulnerability in Claude Cowork for macOS that allowed a VM to read and write all over the Mac

Author: Published 4 min de lectura 228 reading

The images in this article were generated with artificial intelligence. How we publish

Security researchers have revealed critical vulnerability in Anthropic Claude Cowork's desktop version for macOS that allowed an agent to escape from his Linux virtual machine and read or write files throughout the Mac system where the local session was running. The finding, baptized as SharedRoot by those who discovered it, it exposes the real risk of running local VMs-based agents with extensive file system assemblies and network capabilities without appropriate restrictions.

According to the company that reported the failure, Accomplish AI, the technique worked because the guest VM mounted the host's file system with lectura- writing access at a point accessible to the root user within the guest. A chain of operation took advantage of the ability to create unprivileged name spaces and the charge of the act _ pedit Linux kernel subsystem to trigger a known overflow on the request COW route (associated with the traffic classification), so the process in the VM obtained root-equivalent privileges in the guest and, through shared assembly, access to the entire user's Mac.

SharedRoot: the vulnerability in Claude Cowork for macOS that allowed a VM to read and write all over the Mac
Image generated with IA.

The practical danger is simple and serious: an agent that achieves this climbing can read SSH keys, stored credentials, cloud tokens files and other user secrets that run the application on the desktop. The discoverers estimated that up to half a million local authorities could have been exposed before Anthropic changed the default behavior to cloud execution.

Anthropic responded by closing the report as informative and changing the default execution to the cloud, which reduces the attack vector for most users. However, those who explicitly choose to run local Cowork sessions remain at risk if they do not apply additional mitigation or if the kernel / VM image is not patched. This episode highlights a major lesson: the ergonomics of running locally can collide with structural security limitations when the design relies on shared assemblies and kernel modules that can be exploited from an unprivileged context.

From a technical point of view, vulnerability is representative of a recurring class in network subsystems and kernel programming: a module that is self-propelled, a configuration route accessible by non-privileges users and a memory failure that turns that route into an effective scaling of privileges. In summary, patching a specific CVE resolves that instance, but leaves intact the pattern that will allow the next similar failure to arise if structural containment measures are not implemented.

For users using Claude Cowork in macOS I recommend, in this order: to ensure that the application is up-to-date and to prefer cloud execution if it is not necessary to work in local; to review preferences and avoid sharing the root of the system (/) with the VM; to mount only the specific folders required by the session and, where possible, to do so in reading mode; and to rotate keys and credentials if it is suspected that a local session may have been compromised. It is also appropriate to audit recent files and system records by unusual activity and, in doubt, to revoke tokens or SSH keys and generate them again.

For administrators and developers of solutions that incorporate agents in VMs, the practical technical recommendations are clear: not to mount the entire host system with writing permits in the VM; limit the capabilities that are given to the user process within the container or VM (avoid CAP _ NET _ ADMIN if not strictly necessary); disable or restrict non-privileged name spaces when the environment allows; harden seccomp filters to reduce allowed calls; prevent the self-use of kernel modules from exposed contexts; and run management processes such as cod in a user-based and user-based reassembly system for not only to be implemented by a user-friendly and user-friendly system to be implemented.

SharedRoot: the vulnerability in Claude Cowork for macOS that allowed a VM to read and write all over the Mac
Image generated with IA.

In addition to these specific measures, it is appropriate to take an in-depth defence approach: to contain the impact of a possible escalation of the VM, even with guest-root, there are no easy vectors to attack the host. Read-only assemblies, lower exposure of virtual devices and a clear policy on when it is acceptable to run models locally against running in the cloud help reduce the exposure window.

This incident recalls the tension between offline functionality and security: the ability to run complex agents on a local team has latency and privacy advantages, but requires stricter controls on the isolation of the VMs and the kernel. Meanwhile, suppliers should prioritize not only reactive patches, but also design changes that eliminate the dependence on repeatable operating roads.

If you are looking for technical reference documentation on the Apple virtualization framework and on how Linux manages name and capacity spaces, you can see the official Apple documentation on Apple Virtualization Framework and the kernel guide in kernel. Keeping informed and implementing mitigation measures is the most practical way to reduce risk while the community corrects the attack surface.

Coverage

Related

More news on the same subject.