The record
Written from the 2 reports below. Nothing here is unsourced.
- CVE-2026-46331 was disclosed as a high-severity Linux kernel vulnerability in the net/sched subsystem, where partial copy-on-write handling in the tcf_pedit_act() function can corrupt the page cache, potentially enabling local privilege escalation or denial of service.
- The issue affects systems with unprivileged user namespaces enabled, overly permissive seccomp filters, or module autoloading.
- Separately, researchers from Accomplish AI also disclosed a sandbox escape flaw in Anthropic's Claude Cowork product for local macOS sessions.
- In response, Anthropic has moved newer Claude Cowork versions to default to secure cloud execution, reducing local attack surface.
- For the Linux kernel flaw, a patch is available, and mitigations include disabling unprivileged user namespaces, tightening seccomp filters, and restricting host filesystem sharing into VMs.
- No public exploits are confirmed yet, but PoCs exist.
- Organizations running Linux workloads, especially containers and VMs, should prioritize kernel patching and review namespace and seccomp configurations.
What to watch next
- Patch Linux kernel immediately for CVE-2026-46331
- Disable unprivileged user namespaces where possible
- Audit seccomp filters and VM host-sharing configs
- Upgrade Claude Cowork to cloud-default versions
What changed2
Every report on this story, newest first. Times are when each outlet published.
Why it matters4
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Linux kernel (net/sched pedit) page cache corruption· immediate
- Linux users on systems with unprivileged user namespaces privilege escalation risk· days
- Anthropic Claude Cowork local macOS users sandbox escape risk· immediate
- Anthropic Claude Cowork secure cloud migration· weeks
Coverage2
2 reports
English national1Wire / agency1
Filed from India ×1, United States ×1
Named India · Claude Cowork · Linux · Accomplish AI · Anthropic · Apple · Hiltch · Oren Yomtov
- The Hacker NewsClaude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files[1]English national· neutral

- NVD / CVECVE-2026-46331: In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes[2]Wire / agency
The 2 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.