Claude Cowork sandbox escape can read your Mac's SSH keys and creds

Anthropic closed the report without a fix and defaults to cloud runs, leaving local Mac users exposed — Hetzner opens a free OpenAI-compatible Qwen endpoint.

Nowline JUL 24 9:00 PM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • One kernel bug, and the VM isn't a wall anymore

    Accomplish AI's SharedRoot disclosure chains CVE-2026-46331, a Linux-kernel privilege escalation, with Cowork mounting your entire Mac home directory read-write into its Linux VM — so a single crafted session can reach guest-root and read SSH keys, cloud credentials, and anything your macOS account can. Researchers put roughly 500,000 local sessions in range before mitigation.

  • Anthropic's fix is 'run it in the cloud'

    Anthropic closed the report as informative without patching the escape, and instead shipped a Cowork build that defaults to cloud execution; anyone who still opts into local execution stays exposed. If you run Cowork or Claude Code locally on a Mac, move to cloud runs or limit folder sharing to read-only, connected folders only.

  • Hetzner quietly opens a free Qwen endpoint

    Hetzner is testing an OpenAI-compatible Inference API serving Qwen3.6-35B-A3B (35B MoE, 3B active, FP8) at a 262K-token context, free during the experiment with no billing or SLA. Point any OpenAI client at inference.hetzner.com/api/v1 with an Experiments token — one first look clocked 153 ms to first token and ~224 tokens/sec, a cheap European alternative to OpenRouter or Together.