For some time now, Claude Cowork has been attracting attention for its ability to grant full access to a Mac without requesting any authorization. This feature raises major questions about security and the protection of personal data. Far from being a mere gimmick, this system poses a real challenge to access control management on macOS.
When Claude Desktop is launched in Cowork mode, the Anthropic agent is granted extensive file and folder manipulation access. At first glance, everything appears confined within the sandbox of the Linux virtual machine. However, security researchers have revealed that this enclosure is far more porous than it seems. It’s an open door to complete access, without any warning signs.
Claude Cowork on Mac: freedom of access that raises security concerns
The fundamental principle of automated agents is to operate in a strictly controlled space, generally linked to a specific file. A closed environment where observation can be carried out with complete confidence. However, at Claude Cowork, this sandbox looks more like a marked line on the floor than a protective wall.
In practice, a folder is mounted in a Linux virtual machine without elevated privileges. Theoretically reassuring. But it’s the entire Mac root directory that’s mounted with read-write access, accessible to the superuser on the virtual machine. In other words, the vault is located in the system’s lobby, with the only guarantee being that the key remains on a high shelf.
Impact and technical implications of this exhibition
Thanks to this configuration, Claude can freely browse all the data stored on the Mac. SSH keys, online service credentials, and sensitive files become just a click away. The agent’s capabilities even extend to modifying or creating content in any folder, without triggering any authorization prompts.
Researchers at Accomplish AI, who made the discovery, estimate that more than 500,000 macOS users were potentially exposed before Anthropic modified the system’s functionality. Fortunately, no malicious exploitation attempts were observed in real-world conditions.
Anthropic reactions to discovery: between minimization and partial corrective measures
Alerted to this potential vulnerability, Anthropic has essentially shifted the problem. Rather than fixing the core of the vulnerability, the latest version of the tool now performs most operations via remote servers. This switch closes the local attack path for users who have switched over, but does nothing for those who remain in local mode.
The recommended workaround—preventing the automatic loading of unnecessary Linux kernel modules—has not been extended to all modules. However, it is partially implemented to address a previous vulnerability. It’s a bit like building a dam for a flood while forgetting about the other side.
Consequences for system administrators and Linux/macOS users
For those who manage infrastructure or ensure workstation stability, this information serves as a reminder that a poorly implemented isolation mechanism can quickly turn into a nightmare. Sandboxing techniques are not all created equal, especially when mixing virtual Linux environments and macOS systems.
In this specific case, privileged access is akin to having a key under the door. Ignoring this vulnerability is like leaving the barn door wide open during a storm. At this stage, there’s no guarantee that another storm won’t pass.
Claude Cowork: a powerful tool to be handled with care
This ability to grant full access without requiring authorization offers clear advantages for automating repetitive tasks, improving workflows, and overcoming the usual limitations of graphical interfaces. However, it requires a clear awareness of the inherent risks.
The official documentation recommends thoroughly understanding the scope of access granted. To learn more, it is helpful to consult a comprehensive beginner’s guide that details the operation step by step. This helps avoid confusing power with a lack of vigilance.
Finally, this case illustrates a fundamental point of free and open-source software: the need to examine and test any security mechanism yourself. Not blindly trusting tools, however advanced they may be, means maintaining control over your system.
For more in-depth information, see a detailed article on this topic, as well as a complete technical analysis in a specialized source. There you will find all the keys to better mastering Claude Cowork and its access management on Mac.
Can Claude Cowork access all my files without my knowledge?
Yes, Claude Cowork can have full access to the Mac’s hard drive without displaying any authorization windows, in the current configuration. This relies on how the agent is integrated into a Linux virtual machine and access to the mounted filesystem in read/write mode.
Has Anthropic fixed this security vulnerability?
The company mitigated this risk by running Claude Cowork on remote servers by default. However, the local patch was not applied to completely stop extended access on machines still running in local mode.
Comment limiter les risques d’exposition sur macOS ?
It is recommended to restrict the loading of unnecessary kernel modules in the virtual machine and avoid sharing more than strictly necessary with the agent. Regularly monitoring Anthropic updates is also crucial.
Why is a Linux virtual machine being used in this context?
Using a VM allows the agent to be isolated in a controlled environment with limited privileges. However, in this case, virtualization alone is not enough to prevent extensive access to the host system due to the disk’s extended mounting.
Can Claude Cowork be useful despite these risks?
Absolutely, this agent offers powerful automation and can facilitate many tasks. However, its use should always be accompanied by increased vigilance regarding permissions and system configuration.
For a more complete and technical overview, see [link to relevant page]. this in-depth investigation and a complete guide for beginners who decipher these phenomena.
Source: www.01net.com