Mark RadarMARK RADAR
EN

Claude Sandbox Flaw Allegedly Enables Root Access to Virtual Machine

1 reports · First detected 2026-07-06 · Last active 2026-07-06

Anthropic’s Claude Cowork is a knowledge-work automation tool whose Windows version runs Claude Code inside a Hyper-V-isolated Ubuntu virtual machine, with restricted permissions and external network access. The sandbox serves as a security boundary between the host and the AI software. If bypassed, an attacker could potentially read session data within the same virtual machine and even modify protective components.

On July 1, 2026, Armadin disclosed an attack chain it had verified in version 1.9255.2.0. The chain uses DLL sideloading to make claude.exe pass checks by a local service, then exploits parameters to obtain root access and remove restrictions on external connections. The team reported the issue on March 20. On March 24, Anthropic declined to classify it as a security issue, saying an attacker would first need the ability to run a program on Windows.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR