Armadin details full sandbox escape in Claude Cowork but Anthropic disputes risk
Claude's sandbox just broke. Anthropic says it doesn't matter. Security researchers disagree.

Why it matters
A disclosed sandbox escape in Claude Cowork raises questions about the security posture of production AI agent infrastructure—especially as enterprises deploy models in sensitive environments. Anthropic's dismissal of the risk highlights the ongoing friction between security researchers and AI labs over threat modeling.
The key facts
6 to knowFull sandbox escape chain detailed by Armadin Inc.
Attack achieves arbitrary root command execution inside Claude Cowork sandbox
Second flaw strips network restrictions meant to contain the exploit
Anthropic disputes the severity/risk classification
Reported via responsible disclosure (March timeline implied)
Deployment context: Claude Cowork is Anthropic's agent/code-execution product
Go to the source
SiliconAnglesiliconangle.com
Publisher excerpt: Security researchers at Armadin Inc. today detailed an attack chain that runs arbitrary commands as root inside the sandbox behind Anthropic PBC’s Claude Cowork, escaping the isolation layer, with a second flaw stripping the network restrictions meant to contain it. Anthropic, however, does not…