Introducing SharedRoot vulnerability: we recently found and reported several sandbox escape vulnerabilities to
@AnthropicAI, and today we want to share one of these.
I think most people don't understand the severity of the situation we are facing, with AI-assisted kernel bug-finding industrializing. Sandboxes are structurally one N-day behind, all the time, so containment can't lean on a guest Linux kernel being clean.
SharedRoot enables escaping the Cowork VM (a kernel-level isolated solution, which is considered much more secure than the sandbox that ships with codex or claude code), allowing an attacker to gain unauthorized access to the user’s computer.
Exploiting the SharedRoot vulnerability uncovered by the
@Accomplish_ai research team, a user who is certain Cowork only has access to a specific uploaded folder on their computer - actually exposes their entire contents of their computer to an attacker leveraging the Cowork vulnerability.
Read about the full technical details of the attack chain in our blog post by
@orenyomtov below -->