A vulnerability was found on Claude Cowork.
A vulnerability was found on Claude Cowork, resulting in an AI Agent gaining access to files on a Mac.
According to a report by the website, Mezha has mentioned the detection of vulnerabilities on the Claude Cowork tool on the local version of macOS that can allow Claude Cowork to escape the virtualization machine and access files on the machine, including key data files such as passwords for cloud applications and SSH keys. According to a research team from Accomplish AI, an AI agent, the vulnerability could affect up to 5 lakh Claude Cowork users on macOS. Quite a case.
The research team has revealed that the vulnerability is named SharedWork, a bug-based vulnerability within the core of Linux, coded CVE-2026-46331. The AI uses this vulnerability to upgrade the right to access the system to the highest level, or ROOT, within the guest Virtual Machine, resulting in the AI being able to escape the Virtual Machine environment through mounted system files with write permissions, leading to the ability to access all data on the machine by the AI.
The research team has already reported to Anthropic, the developer of Claude Cowork, but instead of issuing an update to fix the vulnerability, the company closed the case in an acknowledgement or Informational state and did nothing instead. The new version of Claude Cowork has a default setting to Cloud Execution, which bypasses Claude Cowork from being able to break through the traditional virtual system, but does not fix the problem for those who use Claude Cowork locally.
จากประสบการณ์การใช้งาน AI Agent และเครื่องมือแบบ Local บน macOS พบว่าช่องโหว่ที่เกิดขึ้นอย่าง SharedWork มีผลกระทบรุนแรงมากกว่าที่หลายคนคาดคิด เหตุผลเพราะ Claude Cowork ใช้ Virtual Machine ในการจำลองสภาพแวดล้อมเพื่อความปลอดภัยโดยปกติ แต่ช่องโหว่ CVE-2026-46331 นี้ทำให้ AI Agent สามารถถอนตัวออกมาจาก Virtual Machine แล้วเข้าถึงไฟล์ระบบจริงบนเครื่อง Mac ได้ โดยใช้สิทธิ์ ROOT ผ่านระบบ User Namespace เหมือนกับการข้ามกำแพงความปลอดภัยแบบแอบแฝง ในมุมมองผู้ใช้ทั่วไป การติดตั้งและใช้งานเวอร์ชัน Local อาจสะดวกและรวดเร็วมากกว่าการประมวลผลบนคลาวด์ แต่ก็นำมาซึ่งความเสี่ยงด้านความปลอดภัยโดยที่ผู้ใช้เองไม่ทันตั้งตัว การที่บริษัท Anthropic เลือกจะรับทราบช่องโหว่โดยไม่แจกแพตช์แก้ไขโดยตรง อาจทำให้ผู้ใช้ที่ยังต้องใช้งาน Local OS เสี่ยงกับการถูกโจมตีข้อมูลสำคัญ เช่น รหัสผ่านคลาวด์, กุญแจ SSH หรือแม้แต่ไฟล์ส่วนตัวที่ไม่ได้ตั้งใจเปิดเผย คำแนะนำสำหรับผู้ที่ใช้งาน Claude Cowork บน macOS คือ ควรพิจารณาย้ายไปใช้เวอร์ชัน Cloud Execution ซึ่งจะช่วยป้องกันการเข้าถึงไฟล์โดยไม่ได้รับอนุญาต หรือหากจำเป็นต้องใช้เวอร์ชัน Local ก็ควรจำกัดสิทธิ์ในการใช้งานอย่างเข้มงวด รวมถึงติดตามประกาศและแพตช์จากผู้พัฒนาอย่างใกล้ชิด นอกจากนี้ ผู้ใช้งานควรประเมินความจำเป็นของแต่ละขั้นตอน และตั้งค่าระบบความปลอดภัยให้เหมาะสมกับลักษณะการใช้งาน เพื่อป้องกันข้อมูลสำคัญรั่วไหล ควบคู่กับการศึกษาและทำความเข้าใจความเสี่ยงของการใช้งาน AI Agent ในสภาพแวดล้อมจำลองจริง สุดท้ายนี้ ช่องโหว่ SharedWork บน Claude Cowork เป็นตัวอย่างที่ชัดเจนว่าแม้เทคโนโลยี AI จะก้าวหน้า แต่การรักษาความปลอดภัยของระบบปฏิบัติการและสภาพแวดล้อมจำลองยังคงเป็นหัวใจสำคัญ หากไม่รีบแก้ไข อาจทำให้เกิดเหตุการโจมตีที่กระทบกว้างและรุนแรงขึ้นในอนาคต
