The ReadJuly 1, 2026via SiliconAngle
Armadin details full sandbox escape in Claude Cowork but Anthropic disputes risk
Why it matters
A disclosed sandbox escape in Claude Cowork raises questions about the security posture of production AI agent infrastructure—especially as enterprises deploy models in sensitive environments. Anthropic's dismissal of the risk highlights the ongoing friction between security researchers and AI labs over threat modeling.
Key signals
- Full sandbox escape chain detailed by Armadin Inc.
- Attack achieves arbitrary root command execution inside Claude Cowork sandbox
- Second flaw strips network restrictions meant to contain the exploit
- Anthropic disputes the severity/risk classification
- Reported via responsible disclosure (March timeline implied)
- Deployment context: Claude Cowork is Anthropic's agent/code-execution product
The hook
Claude's sandbox just broke. Anthropic says it doesn't matter. Security researchers disagree.
Security researchers at Armadin Inc. today detailed an attack chain that runs arbitrary commands as root inside the sandbox behind Anthropic PBC’s Claude Cowork, escaping the isolation layer, with a second flaw stripping the network restrictions meant to contain it. Anthropic, however, does not consider it a security issue. Armadin reported the chain on March […]