Anthropic-linked researchers detail SharedRoot, a sandbox escape that can expose a host filesystem
EdenEmarco177 · x · 2026-07-24
Researchers said they found and reported multiple sandbox-escape vulnerabilities to Anthropic, and are now highlighting one called SharedRoot.
- The team argues AI-assisted kernel bug-finding is making such attacks more industrialized.
- Their claim: sandboxes are always effectively one N-day behind, so containment cannot rely on a clean guest Linux kernel.
- SharedRoot allegedly escapes the Cowork VM isolation layer and can grant unauthorized access to a user's computer, including the entire contents of the exposed filesystem.
More from coding & agent
- Induction Labs says Photon-1 learned computer use from 18 years of unlabeled screen video — ycombinator · 2026-07-24
- OpenWorker debuts as an open-source agent that delivers finished work across apps — daniel_mac8 · 2026-07-24
- Andrew Ng launches OpenWorker, an open-source agent that delivers finished work — AndrewYNg · 2026-07-24
- Frontier-Bench debuts with 74 tasks and top agents scoring about 34% — giswqs · 2026-07-24
- Notion beta lets teams define entire workspaces in TypeScript and deploy via API — thesaraharminta · 2026-07-24
- Anthropic engineer says teams are moving from prompts to graph-orchestrated self-improving agents — colinmcnamara · 2026-07-24