• Sources: Accomplish AI writeup, CVE-2026-46331 (NVD), r/netsec
  • Summary: A writeup published 2026-07-23 chains six steps to break out of the Linux VM that Claude Cowork uses to sandbox agents on macOS. An agent opens an unprivileged user namespace to gain capabilities inside it, uses CAP_NET_ADMIN to configure a traffic-control action referencing the act_pedit kernel module, exploits CVE-2026-46331 to poison the page cache of a root-owned helper binary, gains guest root when the coworkd daemon re-executes it, then reaches /mnt/.virtiofs-root, the host filesystem mounted read-write into the VM, and reads and writes files outside the folder the user connected. The researchers report Anthropic closed the report as informative because the underlying CVE was already public, and state Cowork now defaults to cloud execution where the local path does not appear to apply. The proposed mitigations are design-level: disable unprivileged user namespaces, harden seccomp filtering, block autoloading of unused modules, and narrow the host filesystem share.
  • Why it matters: The sandbox boundary agent tools advertise is only as strong as the guest kernel plus the host mount, and a public month-old kernel bug was enough to cross both.
  • Follow-up: Watch for a Cowork change that removes the read-write host mount or blocks unprivileged user namespaces, and for the same chain against other VM-based agent sandboxes.

send feedback on this story