Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News AI News

A Claude Cowork sandbox-escape flaw (CVE-2026-46331, "SharedRoot")

Let local sessions on Mac mount the host filesystem inside the guest VM with full read/write, reachable up to SSH keys and cloud credentials. Anthropic.

Enterprise DNA |
A Claude Cowork sandbox-escape flaw (CVE-2026-46331, "SharedRoot")

AI Pulse · AI Trends Pulse

The play

If you run agents locally on Mac, move sandbox workloads to remote or containerized environments, the local VM escape risk is real and unfixed.

Anthropic’s Claude Cowork tool, which lets the AI agent run code and commands on your machine, had a sandbox-escape flaw that could have given a rogue or tricked agent full read-write access to your host filesystem. That includes SSH keys, cloud credentials, and anything else sitting on your Mac. The vulnerability, tracked as CVE-2026-46331 and nicknamed “SharedRoot,” affected local sessions where Cowork spun up a guest virtual machine but accidentally mounted the host’s root directory inside it.

Anthropic marked the disclosure as “informative” and did not issue a direct patch. Instead, the company changed Cowork’s default behaviour so sessions now run remotely on Anthropic’s own servers rather than locally on your machine. That sidesteps the immediate risk but shifts the trust model entirely. You are no longer worried about an agent escaping a local VM, you are trusting Anthropic’s infrastructure to isolate your session from everyone else’s.

This is the second agent-sandboxing story in the same week, following the Share-link leak that exposed session data through URL tokens. The pattern matters. Agentic tools are moving fast, and isolation boundaries are still being worked out in production. If you are running AI agents with access to your codebase, file system, or internal APIs, you need a clear picture of what they can reach and how they are contained. The Hacker News has the technical breakdown.

For teams deploying agents at scale, tracking which tools run where, what permissions they hold, and when defaults change is exactly the kind of operational visibility we build into the Omni Command Centre. Sandboxing is not a one-time checkbox. It is an ongoing posture question, and you want the answer in front of you before the next CVE drops.

Working With Claude field guide cover

Free Resource

Put what you just read to work

The free 32-page Working With Claude guide: the full ecosystem, Claude Code, and how to roll it out across a business.

No spam. Unsubscribe any time.

Free daily email

Get this every morning.

This brief is one item from today's AI Pulse, the short daily read we run for ourselves on what is actually happening in AI. Subscribe free and it lands in your inbox each morning.

Free daily email

Subscribe to the daily AI Pulse

One short read every morning on what is actually happening in AI. Free.

One email a day. Unsubscribe any time.