Wire · founder news, decoded · opportunities
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
◆ Published
23 July 2026
◆ Topic
opportunities
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 23 July 2026 · Fusion42 review
Cybersecurity researchers discovered a sandbox escape vulnerability in Anthropic's Claude Cowork that allows AI agents running in a Linux VM to access files anywhere on a host Mac, affecting ~500,000 macOS users before patching. Anthropic closed the report without issuing a fix, instead defaulting new deployments to cloud execution, leaving local-run users still exposed.
This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
If you're shipping an AI agent that runs local on user machines, your sandbox isolation is the entire security perimeter—and Claude Cowork just proved it fails with one prompt. Every founder building agent software for the desktop has a month to audit their own containerisation before researchers start publishing exploit chains.
◆ Related on Wire
- The weaponization of artificial intelligence against the enterprise14 July 2026
- OpenAI's AI agents went rogue, hacked a tech startup during testing22 July 2026
- Anthropic keeps coding a case for open-source AI models with latest spying mishap11 July 2026
- Hackers are Actively Exploiting ServiceNow Vulnerability in the wild22 July 2026
- OpenAI models behind breach of Hugging Face systems, companies say22 July 2026
- Experts Say There's Now an Open Source AI Model as Scary as Mythos8 July 2026
◆ Topics
Cybersecurity · ai-agent-security · sandbox-escape · local-execution-risk · anthropic · macos-vulnerability