Risk for half a million users: the vulnerability that exposes files on your computer

Would you allow an AI-based digital assistant to manage tasks for you directly on your personal computer? The idea sounds great and promises to save us valuable time, but it turns out it also brings significant security risks.

Source
Risk for half a million users: the vulnerability that exposes files on your computer
Photo: Now14 / צילום: שאטרסטוק

Would you allow an AI-based digital assistant to manage tasks for you directly on your personal computer? The idea sounds great and promises to save us valuable time, but it turns out it also brings significant security risks. Security researchers recently revealed that about half a million Mac computer users who used the popular AI tool "Claude Cowork" were exposed to a serious security flaw that allowed attackers to obtain full access to their files and sensitive passwords.

What is the flaw and how does it work?

The tool from the company Anthropic is intended to help users by accessing selected files and folders on the computer. To prevent harm or misuse, the tool operates within a "sandbox" (an isolated virtual environment) that is supposed to limit its access. However, security researchers from the company Accomplish AI discovered a weakness that earned the name SharedRoot. Using only a single short message, attackers could easily breach these boundaries, bypass the protection mechanisms, and obtain full read and write permissions for every file on the Mac computer, without needing user approval.

This serious flaw not only endangered personal files, but also enabled potential attackers to access login details and passwords of various online services stored on the computer. The company Anthropic was quick to respond and changed the default settings of the new version of Claude Cowork, so that it now operates through a secure cloud rather than locally on the computer. However, it turns out that many users who chose to continue running the tool locally on their computer are still exposed to this real danger.

How to protect your computer

If you prefer to run the AI agent locally on your Mac, you must take manual steps to secure the system. The researchers recommend disabling namespaces for unauthorized users, limiting file sharing, and running Cowork’s background software with strict anchoring protections. These steps will ensure that your computer remains protected against exploitation of the flaw.

Related News