Skip to finding
important · Agent sandbox

A file written by a compromised Cowork agent can execute on the macOS host when opened.

Affects

Claude Desktop for macOS, including its Cowork virtual-machine workspace and host file-opening integration.

Claude Desktop omitted one executable file type from its denylist. A compromised or prompt-injected agent can write that type into the shared Cowork folder, but this standalone path still requires the user to open it.

Detail and 1 source
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 27, 2026