WorkThe story, in brief

Armadin details full sandbox escape in Claude Cowork but Anthropic disputes risk

Claude's sandbox just broke. Anthropic says it doesn't matter. Security researchers disagree.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A disclosed sandbox escape in Claude Cowork raises questions about the security posture of production AI agent infrastructure—especially as enterprises deploy models in sensitive environments. Anthropic's dismissal of the risk highlights the ongoing friction between security researchers and AI labs over threat modeling.

The key facts

6 to know
  1. Full sandbox escape chain detailed by Armadin Inc.

  2. Attack achieves arbitrary root command execution inside Claude Cowork sandbox

  3. Second flaw strips network restrictions meant to contain the exploit

  4. Anthropic disputes the severity/risk classification

  5. Reported via responsible disclosure (March timeline implied)

  6. Deployment context: Claude Cowork is Anthropic's agent/code-execution product

Go to the source

SiliconAnglesiliconangle.com

Publisher excerpt: Security researchers at Armadin Inc. today detailed an attack chain that runs arbitrary commands as root inside the sandbox behind Anthropic PBC’s Claude Cowork, escaping the isolation layer, with a second flaw stripping the network restrictions meant to contain it. Anthropic, however, does not…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work