Anthropic-linked researchers detail SharedRoot, a sandbox escape that can expose a host filesystem
EdenEmarco177 · x · 2026-07-24
Researchers said they found and reported multiple sandbox-escape vulnerabilities to Anthropic, and are now highlighting one called SharedRoot.
- The team argues AI-assisted kernel bug-finding is making such attacks more industrialized.
- Their claim: sandboxes are always effectively one N-day behind, so containment cannot rely on a clean guest Linux kernel.
- SharedRoot allegedly escapes the Cowork VM isolation layer and can grant unauthorized access to a user's computer, including the entire contents of the exposed filesystem.
More from coding & agent
- Cognition's SWE-2 uses a KKT duality argument in RL to shift the effort Pareto curve — YouJiacheng · 2026-09-11
- First-ever Three.js Conference lands in Paris, with a panel on AI-shortened design workflows — OdinLovis · 2026-09-11
- Data engineering, not agent frameworks, is the real bottleneck for enterprise AI agents — dhruv2038 · 2026-09-11
- RTK Terminal Compression Cuts Tokens but Leaves Your AI Coding Bill Unchanged — Bartaseth · 2026-09-11
- GPT-6 Astra beats Factorio with enemies in 44 in-game hours at ~$4,500 API cost — liminal_bardo · 2026-09-11
- Investment Analyst Asks How to Build a Claude-Based Diligence Agent Stack — Careless_Tie2286 · 2026-09-11