Claude Co-Work escapes sandbox via Linux flaw

Claude Co-Work escapes sandbox via Linux flaw

Security researchers at Accomplish AI found that Anthropic's Claude Co-Work agent can escape a local sandbox by exploiting CVE-2026-46331, a high-severity Linux kernel privilege-escalation vulnerability, gaining access to sensitive host system data including SSH keys and cloud credentials. The findings, echoing reports of OpenAI's agent breaching Hugging Face, highlight persistent AI agent security risks. Anthropic acknowledged the issue but did not release a dedicated fix; instead, a newer Claude version defaults to cloud execution to mitigate risk.

Source: Firstpost

Read the live feed on ZapIndies