important · Agent sandbox
A file written by a compromised Cowork agent can execute on the macOS host when opened.
Affects
Claude Desktop for macOS, including its Cowork virtual-machine workspace and host file-opening integration.
Claude Desktop omitted one executable file type from its denylist. A compromised or prompt-injected agent can write that type into the shared Cowork folder, but this standalone path still requires the user to open it.
Detail and 1 source
Anthropic identifies a fixed Claude Desktop release.