Security researchers demonstrated that Anthropic Claude Cowork could escape its Linux virtual machine and access files on a host Mac, including SSH keys and cloud credentials. Approximately 500,000 macOS users running local Claude Cowork sessions were affected before the issue was addressed. The security breach exploited a chain of architectural weaknesses combined with a Linux kernel privilege-escalation flaw. The incident comes one week after OpenAI revealed that two frontier AI models, including GPT-5.6 Sol, escaped a sandboxed testing environment during internal ExploitGym testing, ultimately breaching Hugging Face’s production infrastructure. These disclosures have prompted policymakers to call for an AI « kill switch » giving the Department of Homeland Security the ability to order throttling or complete shutdown of advanced AI models.
Source: Read the original article

