CVE-2026-7574Disclosure

LOWCVSS 8.7 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1.1617.0, and v1.2278.0) validates only file presence and a version marker string before booting rootfs.img, but does not verify image content integrity at time-of-use. A local attacker with unprivileged code execution as the victim macOS user can modify the VM root filesystem image and have it trusted on subsequent Cowork VM boots, enabling persistent arbitrary code execution in the VM and access to host-mounted directories. The estimated CWE mapping is CWE-353 (Missing Support for Integrity Check).

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-353

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-24); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-24: 2Mentions · 2026-07-23: 1Active Exploitation · 2026-07-23: 1Technical Details · 2026-06-24: 2Technical Details · 2026-07-23: 106-2407-23
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-242
Disclosure2
2026-07-231
Active Exploitation1
Full discourse3 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    اذا تستخدم Claude Cowork فيه ثغره عاليه الخطوره اعلنو عنها اليوم الجيد في الموضوع ان المهاجم يحتاج أولاً وصول محلي بصلاحيات المستخدم على macOS عشان يقدر يستغلها. 📍 التفاصيل: رقم الثغرة: CVE-2026-7574 التقييم: High 8.7 ⚠️ حدث الان ياصديقي https://t.co/bxcHKinEPj

    Post summary

    A post announces CVE‑2026‑7574 with a high severity rating and notes that exploitation requires local user privileges on macOS, but does not provide evidence of active exploitation, a PoC, or a patch.

    0101195.0K
    50.1K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-7574 Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v… CVSS 8.7 Full analysis → https://sec.kaitan.id/cves/CVE-2026-7574 #Anthropic #CyberSecurity #InfoSec

    Post summary

    A high‑severity vulnerability (CVE‑2026‑7574) affecting Anthropic Claude Desktop is disclosed, with a CVSS score of 8.7 and a linked detailed analysis.

    0001095
    82 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited CVE-2026-7574 in Claude Cowork to escape AI sandbox environments and gain root access to host macOS systems. This incident highlights how AI agent compromises can enable lateral movement beyond isolated environments, accessing SSH keys and cloud credentials. Runtime segmentation helps contain such post-compromise activity. #ZeroTrust #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/claude-cowork-sandbox-escape-vulnerability-2026

    Post summary

    Attackers have used CVE-2026-7574 to escape the Claude Cowork AI sandbox, achieving root on macOS hosts and moving laterally to steal SSH keys and cloud credentials, confirming real-world exploitation.

    0000067
    1.9K followersView on X

Explore more