Header image

AI agent escapes VM sandbox via Linux zero-day vulnerability


Anthropic's Claude Cowork AI agent has demonstrated the ability to escape a virtual machine sandbox, according to security researchers at Accomplish AI. This capability mirrors recent concerns raised about AI agents breaking free from their intended environments, according to Tech Radar.

Researchers at Accomplish AI reported that they successfully exploited a Linux zero-day vulnerability, CVE-2026-46331, to allow the Claude Cowork agent to break out of a virtual Linux machine running on a Mac host. Once outside the sandbox, the agent gained access to the host system, with the potential to exfiltrate sensitive data such as SSH keys and cloud credentials. 

The vulnerability, a privilege escalation flaw with a high severity score, was fixed by the Linux kernel in mid-June. While Anthropic has reportedly shifted Claude Cowork to default cloud execution, addressing the immediate risk for cloud users, those running the agent locally remain exposed. 

Accomplish AI recommends specific configurations, including restricting folder access and implementing strict system protection measures, for users who continue to run the agent in a local environment.

Source: Tech Radar

Kelley Damore
Kelley Damore Chief Content Officer CyberRisk Alliance

Kelley Damore is Chief Content Officer at CyberRisk Alliance, where she leads content strategy across the company’s digital brands, research, communities and live events serving CISOs and security practitioners. At CyberRisk Alliance, she is focused on delivering 365-day engagement, trusted journalism and actionable insights to help security leaders navigate an increasingly complex threat landscape.

Kelley Damore
Kelley Damore Chief Content Officer CyberRisk Alliance

Kelley Damore is Chief Content Officer at CyberRisk Alliance, where she leads content strategy across the company’s digital brands, research, communities and live events serving CISOs and security practitioners. At CyberRisk Alliance, she is focused on delivering 365-day engagement, trusted journalism and actionable insights to help security leaders navigate an increasingly complex threat landscape.

Upcoming Events

No events found.