One Linux bug gave Claude Cowork access to a Mac’s filesystemAccomplish AI researchers said on July 23 that a locally running Cowork session could exploit a Linux kernel flaw and gain root access inside its virtual machine. Once the session had root access, the agent could reach the Mac’s filesystem through a writable mount.
The researchers called the attack SharedRoot. In their demonstration, they connected one folder to a new Cowork session and gave Claude a single instruction. The agent then read and wrote files outside the approved folder without showing another permission prompt.
Accomplish AI said the accessible files included SSH private keys, cloud credentials, browser data, and other material available to the person logged in to the Mac. The researchers didn’t report evidence that anyone had used SharedRoot against Cowork users outside the controlled test.