A critical sandbox escape vulnerability tracked as CVE-2026-46331, dubbed "SharedRoot," has been found in Anthropic's Claude Cowork product, potentially allowing an AI agent to break free from its Linux virtual machine and access the entire file system of a user's Mac. The flaw strikes at the heart of the security model designed to isolate powerful AI agents from the host system.
The vulnerability was detailed in a disclosure from cybersecurity researchers at Accomplish AI to The Hacker News. It resides within the Linux VM that serves as the sandbox for Claude Cowork — the environment intended to safely execute tasks on behalf of the AI while preventing unauthorized system access to the host macOS system.
SharedRoot enables an agent to circumvent this isolation entirely. Once outside the VM sandbox, the AI would have the potential to read and write files anywhere on the connected Mac. This shifts the risk from a contained application issue to a potential full-system compromise affecting the user's personal data, credentials, and other sensitive information.
The scale of the exposure is significant. Accomplish AI indicates that approximately 500,000 macOS users are currently running the vulnerable version of Claude Cowork, elevating the disclosure from a niche research finding to a widespread consumer security incident requiring urgent action.
For the AI industry, the discovery of SharedRoot serves as a stark validation of long-standing concerns about agentic AI containment. It demonstrates that a single layer of protection — even a VM sandbox — may be insufficient for securely isolating advanced AI models from their host environments. Experts are now advocating for a mandatory shift toward "defense-in-depth" architectures. Such systems would need to combine multiple overlapping safeguards, including granular permission controls, runtime behavioral monitoring, and continuous validation of agent actions, rather than relying on one barrier of defense.
Anthropic's forthcoming response will be a critical test for the young AI security sector. The company's speed in patching CVE-2026-46331 and its transparency in communicating with its large user base will set an important precedent. Users are advised to apply any security updates from Anthropic immediately upon release and to assume that any AI agent operating under the now-untrusted sandbox could have compromised host system integrity.
This incident moves the abstract debate about AI containment into the real world of operational cybersecurity. As AI agents gain greater ability to interact with host operating systems, the security frameworks protecting those systems must evolve with equal speed to prevent breaches of trust and safety.
一個被追蹤編號為CVE-2026-46331、代號「SharedRoot」的關鍵沙箱逃脫漏洞,已在Anthropic的Claude Cowork產品中被發現,可能令人工智能代理從其Linux虛擬機中脫離,存取用戶Mac電腦的整個檔案系統。此漏洞衝擊了旨在將強大AI代理與主機系統隔離的核心安全模型。
網絡安全研究人員Accomplish AI向The Hacker News提供的披露中詳細說明了該漏洞。它存在於作為Claude Cowork沙箱的Linux虛擬機中——此環境本意是安全地代AI執行任務,同時防止對macOS主機系統的未授權存取。
SharedRoot漏洞使代理得以完全規避此隔離。一旦離開虛擬機沙箱,AI將可能在連接的Mac上任何位置讀寫檔案。這使風險從受控的應用程式問題,轉變為可能影響用戶個人資料、憑證及其他敏感資訊的全面系統入侵。
暴露範圍相當廣泛。Accomplish AI指出,目前約有50萬名macOS用戶正運行該漏洞版本的Claude Cowork,使此次披露從小眾的研究發現,升級為需要緊急處理的大規模消費者安全事故。
對人工智能產業而言,SharedRoot的發現為長期存在的代理式AI containment擔憂提供了嚴峻的驗證。它表明單一保護層——即使是虛擬機沙箱——可能不足以將先進AI模型與其主機環境安全隔離。專家現正提倡必須轉向「縱深防禦」架構。此類系統需要結合多重疊加的安全措施,包括細粒度權限控制、運行時行為監控,以及對代理行動的持續驗證,而非依賴單一防禦屏障。
Anthropic即將作出的回應將是這個年輕AI安全領域的關鍵考驗。該公司修補CVE-2026-46331的速度,及其與龐大用戶群溝通的透明度,將樹立重要先例。用戶被建議在發布後立即應用任何Anthropic的安全更新,並應假設任何在現已不受信任的沙箱下運行的AI代理,可能已破壞主機系統的完整性。
此事件將關於AI containment的抽象辯論帶入了實際的網絡安全運作世界。隨著AI代理獲得更強的與主機作業系統互動的能力,保護這些系統的安全框架必須以同等速度進化,以防止信任與安全的破壞。
