Claude Sandbox Flaw Allegedly Enables Root Access to Virtual Machine
Anthropic’s Claude Cowork is a knowledge-work automation tool whose Windows version runs Claude Code inside a Hyper-V-isolated Ubuntu virtual machine, with restricted permissions and external network access. The sandbox serves as a security boundary between the host and the AI software. If bypassed, an attacker could potentially read session data within the same virtual machine and even modify protective components.
On July 1, 2026, Armadin disclosed an attack chain it had verified in version 1.9255.2.0. The chain uses DLL sideloading to make claude.exe pass checks by a local service, then exploits parameters to obtain root access and remove restrictions on external connections. The team reported the issue on March 20. On March 24, Anthropic declined to classify it as a security issue, saying an attacker would first need the ability to run a program on Windows.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.