Anthropic-linked researchers detail SharedRoot, a sandbox escape that can expose a host filesystem
EdenEmarco177 · x · 2026-07-24
Researchers said they found and reported multiple sandbox-escape vulnerabilities to Anthropic, and are now highlighting one called SharedRoot.
- The team argues AI-assisted kernel bug-finding is making such attacks more industrialized.
- Their claim: sandboxes are always effectively one N-day behind, so containment cannot rely on a clean guest Linux kernel.
- SharedRoot allegedly escapes the Cowork VM isolation layer and can grant unauthorized access to a user's computer, including the entire contents of the exposed filesystem.
More from coding & agent
- Anthropic researcher: 99% of engineers now run swarms of 300+ self-improving agents — AlishaOutridge · 2026-09-11
- Gergely Orosz: Shipping 10x PRs With AI Agents, Sites Fill With Small Regressions — ducha_aiki · 2026-09-11
- Same Echo Maze prompt, three frontier models: all passed visually but shipped the same hidden bug — eyishazyer · 2026-09-11
- Astra storyboards plus Minimax H3 per-shot generation boost video success rates — Hailuo_AI · 2026-09-11
- Codex tip: use Sol with Astra and Luna sub-agents to save usage — pvncher · 2026-09-11
- agents-best-practices: a provider-neutral Agent Skill for designing and auditing agentic harnesses — tom_doerr · 2026-09-11