Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-07-22

HighPrimary

SharedRoot (CVE-2026-46331): Claude Cowork VM Escape to Full Mac Host File Access Disclosed

In-depth analysis of CVE-2026-46331 (SharedRoot), a VM-to-host sandbox escape in Anthropic's Claude Cowork allowing full host file read/write.

Claude CoworkGovernance bypassVirtual Machine Escape and Directory TraversalLocal developer workspace / macOS desktop environment

What happened

An agent is fed a short string; it executes an out-of-bounds VM folder mount, allowing it to navigate the host macOS filesystem.

Why it matters

Exfiltration of host macOS SSH keys, private cloud credentials, and sensitive personal files.

Missing authorization check

The VM layer must enforce that any host-filesystem translation request requires a physical human signature receipt.

Would PP block it?

Even if an agent escapes its Linux VM and attempts to access keys or execute host commands, PP's external Runtime and Credential Gates intercept these actions. Since the agent cannot forge a cryptographically-signed authorization receipt from the user's hardware security key, the host file system access and shell command execution fail-close.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-07-22

    Accomplish AI publishes research exposing CVE-2026-46331 sandbox escape in Claude Cowork.

  2. 2026-07-22

    Anthropic closes the vulnerability as informative, transitioning default Cowork runs to cloud execution.

Technical breakdown

  • The agent was given a prompt with a directory-traversal payload mapping to host folders.
  • The Cowork VM's filesystem proxy translated the VM mount points directly into raw host syscalls without origin verification.
  • The agent executed reads on standard credential paths (`~/.ssh`, `~/.aws/credentials`) and exfiltrated them.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Runtime Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Runtime Gate, Credential Gate
Still needs
PP does not block the agent's internal VM file reads that do not cross the integration boundary.
Receipt required for
Accessing host directories, reading SSH keys, or executing local terminal utilities

PP's authorization chain is external to the VM and prevents access to raw keys or files without hardware-key signed receipts.

Start small

Put the relevant gate at this action boundary.

This incident maps to Runtime Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop