Threat reportVulnerabilityTL-2026-1115
Claude Cowork Sandbox Escape: RPC Parameter Bypass Enables Root Command Execution
Claude Cowork Sandbox Escape (TL-2026-1115), also tracked as Claude Cowork Sandbox Escape, is a medium-severity software vulnerability, first published 2026-07-02. It has no confirmed attribution, affects Anthropic, PBC Claude Cowork (Claude Desktop for Windows), maps to 15 MITRE ATT&CK techniques (T1003, T1005, T1057), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-1115
- Threat ID
- TL-2026-1115
- Also known as
- Claude Cowork Sandbox Escape, CoworkVMService isResume Bypass
- Severity
- MEDIUM
- Status
- TRACKING
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, softwaredevelopment, enterpriseit
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in Claude Cowork Sandbox Escape
Malware and tooling: WinVerifyTrust, bubblewrap (bwrap)
How Claude Cowork Sandbox Escape works
Security research firm Armadin publicly disclosed a two-stage exploit chain against Anthropic's Claude Cowork on Windows: DLL sideloading of a malicious USERENV.dll to gain code execution inside the signed claude.exe process, followed by an RPC parameter-validation bypass (isResume: true) against the CoworkVMService spawn method that returns a root shell inside the product's bubblewrap-isolated Linux VM, with a second allowedDomains wildcard bypass defeating the egress proxy. Anthropic disputes the finding as an in-scope security vulnerability because exploitation presupposes an attacker already has local code execution on the Windows host.
Claude Cowork for Windows (packaged as Claude Desktop for Windows, observed at version 1.9255.2.0, installed under the WindowsApps MSIX path) sandboxes agent-executed code inside a Hyper-V Container System (HCS)-isolated Ubuntu Linux VM. Inside that VM, isolation is layered through bubblewrap namespaces, seccomp filtering, per-session unprivileged Linux users, and a domain-restricted egress (MITM) proxy. The host-to-guest control channel is an Authenticode-gated named-pipe RPC service, CoworkVMService, reachable at \\.\pipe\cowork-vm-service, using a simple [4-byte big-endian length][JSON payload] wire framing.
Armadin researcher Nick McClendon first achieved arbitrary code execution inside the legitimately Anthropic-signed claude.exe process via classic DLL search-order hijacking: claude.exe resolves USERENV.dll from its own application directory before falling back to the genuine System32 copy, so a malicious DLL exporting GetUserProfileDirectoryW and named USERENV.dll, dropped alongside claude.exe (found at C:\Program Files\WindowsApps\Claude_1.9255.2.0_x64__pzs8sxrjxfjjc\app\claude.exe), loads and executes inside the trusted, signed process without ever invalidating the running binary's own Authenticode signature.
From that foothold, the researcher used log analysis, JSON fuzzing, and parameter discovery to reverse-engineer the undocumented CoworkVMService RPC protocol, identifying methods including configure, startVM, isGuestConnected, and spawn. CoworkVMService gates pipe connections using WinVerifyTrust to require the connecting process be signed by "Anthropic, PBC" — but this only authenticates the calling binary's publisher, never authorizing or validating the contents of the RPC request itself. The spawn method exposes two undocumented parameters, isResume and allowedDomains. Normally isResume: false forces creation of a fresh unprivileged per-session Linux user for each command; setting isResume: true instead skips the existing-user validation path entirely, letting the daemon execute the requested command as any specified user — including root — with no authorization check. A crafted request such as {"name": "root", "isResume": true} returns an interactive shell with uid=0, full Linux capabilities, and an unconfined AppArmor profile.
From that root shell, still nominally confined by bubblewrap namespaces, the researcher used nsenter targeting PID 1 (nsenter --target 1 --mount --pid --uts --ipc --net) to join the host VM's mount, PID, UTS, IPC, and network namespaces, fully escaping the bwrap sandbox into the broader Hyper-V-isolated Ubuntu guest. A second, independent flaw in the same spawn method allows the allowedDomains parameter to override the VM's network egress allowlist on a per-command basis; while the default proxy configuration returns HTTP 403 for non-allowlisted domains, submitting "allowedDomains": ["*"] grants the sandboxed session unrestricted outbound network connectivity, defeating the domain-restricted egress proxy that is otherwise Cowork's primary control against data exfiltration and untrusted C2 callbacks from agent-executed code.
Claude Cowork itself launched as a research preview on 2026-01-12 as Anthropic's 'computer agent' for non-technical knowledge workers, followed by a wider enterprise rollout in February 2026 adding third-party connectors (Google Drive, Gmail, DocuSign, FactSet). The Windows sandbox architecture Armadin targeted is the same architecture Anthropic later described publicly in its 2026-05-25 engineering post 'How We Contain Claude Across Products,' which documents the VM-based isolation (Apple's Virtualization framework on macOS, HCS on Windows), the bubblewrap/seccomp guest-level layers, and the api.anthropic.com-scoped egress proxy — precisely the control layers Armadin's chain was built to defeat. Inside CoworkVMService, per-session unprivileged-user enforcement is implemented by a backend component the researcher identified as sdk-daemon, which normally invokes useradd to provision a fresh unprivileged Linux account for every non-resumed command; the isResume:true bypass skips this useradd-backed provisioning path entirely, which is the root cause enabling arbitrary-user (including root) command execution. To demonstrate real-world impact beyond a bare root shell, Armadin chained the nsenter host-namespace escape with a live data-exfiltration proof-of-concept: from the escaped VM, the researcher used curl to transmit the contents of /etc/shadow off the sandbox with base64 encoding applied to the payload, showing that both the credential-bearing shadow file and the exfiltration channel itself remained invisible to host-based endpoint defenses because all activity occurred inside the isolated Hyper-V guest rather than on the monitored Windows host.
Armadin reported the full chain to Anthropic on 2026-03-20 under responsible disclosure; Anthropic responded on 2026-03-24 declining to treat it as a qualifying security vulnerability, reasoning that the attack requires the attacker to already possess local code execution on the host — a precondition outside Cowork's stated threat model, which sandboxes agent-generated code rather than defending against an attacker who already owns the host OS. Armadin subsequently published the complete technical write-up and proof-of-concept publicly on 2026-07-01, triggering broad security-press coverage. No CVE has been assigned by MITRE/NVD and the issue does not appear in the CISA Known Exploited Vulnerabilities catalog; there is no evidence of in-the-wild exploitation — this is a disclosed, vendor-disputed, publicly-PoC'd design flaw in Cowork's Windows sandbox rather than an actively exploited campaign. For defenders, the practical exposure is that any local process capable of writing to the Cowork installation directory (e.g., malware already run via other means, a malicious insider, or a supply-chain-compromised auxiliary tool) can pivot local code execution into full root access and full sandbox/VM escape, and separately into unrestricted network egress and credential-file exfiltration from the sandboxed agent session — materially expanding the blast radius of any host that already has some form of local compromise.
MITRE ATT&CK techniques used in TL-2026-1115
Credential Access
Collection
Discovery
T1057 Process Discovery; T1518 Software Discovery
Execution
T1059 Command and Scripting Interpreter; T1106 Native API
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1611 Escape to Host
Command and Control
T1090 Proxy; T1132 Data Encoding
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
Exfiltration
T1567 Exfiltration Over Web Service
stealth
Defense Evasion
Resource Development
privilege-escalation
Affected products and versions in Claude Cowork Sandbox Escape
- Anthropic, PBC — Claude Cowork (Claude Desktop for Windows)
Vulnerable versions: 1.9255.2.0
Remediation for Claude Cowork Sandbox Escape
Patches
- No vendor patch has been released as of 2026-07-05; Anthropic disputes the finding as an in-scope security vulnerability, citing the local-code-execution prerequisite
Immediate actions
- Restrict local write access to the Claude Cowork / Claude Desktop installation directory (e.g., C:\Program Files\WindowsApps\Claude_*) via application allowlisting or Windows Defender Application Control to prevent unauthorized DLL drops alongside claude.exe
- Deploy Sysmon Event ID 7 monitoring for USERENV.dll (or other system DLL) image loads originating from paths outside C:\Windows\System32
- Monitor named-pipe connections to \\.\pipe\cowork-vm-service and alert on spawn RPC requests whose JSON payload contains isResume:true or an allowedDomains value of ["*"] or other wildcard
- Restrict which local users/processes are permitted to open handles to the CoworkVMService named pipe
- Monitor Cowork sandbox VM session activity for reads of /etc/shadow or other credential files followed by outbound curl/HTTP requests carrying base64-encoded payloads, which indicate post-escape data exfiltration invisible to host-based EDR
Workarounds
- Enforce code-integrity / application-control policies preventing untrusted binaries from being written into the Cowork install directory
- Monitor and restrict use of namespace-manipulation tooling (e.g., nsenter) on hosts that run the Cowork Linux VM
- Consider disabling or restricting Claude Cowork on endpoints where local code execution cannot be tightly controlled, until vendor guidance changes
Longer-term hardening
- Track Anthropic's public position and any future remediation of the CoworkVMService spawn method's parameter validation (isResume, allowedDomains)
- Deploy EDR with DLL-sideloading and code-signing-aware execution monitoring on all endpoints running Claude Cowork / Claude Desktop for Windows
- Apply least-privilege and endpoint hardening baselines to hosts running AI coding-agent desktop tools that spawn local VM/container sandboxes, treating 'attacker already has local code execution' as an in-scope threat-model assumption for enterprise risk purposes even where the vendor does not
- Incorporate AI-agent sandbox-escape scenarios (DLL sideloading into signed agent binaries, IPC/RPC parameter abuse, egress-proxy bypass, in-VM credential-file exfiltration) into enterprise threat models and red-team scope for any AI coding-agent deployment
Weaknesses (CWE) in Claude Cowork Sandbox Escape
Timeline of Claude Cowork Sandbox Escape
- Anthropic launches Claude Cowork as a research preview — a desktop 'computer agent' for non-technical users providing a sandboxed shell and local file-system access on Mac and Windows — establishing the product and Hyper-V/bubblewrap sandbox architecture later targeted by Armadin's exploit chain.
- Armadin formally reports the full sandbox-escape exploit chain (DLL sideloading + CoworkVMService spawn RPC parameter bypass) to Anthropic under responsible disclosure.
- Anthropic responds, declining to classify the chain as a qualifying security vulnerability, reasoning that exploitation requires the attacker to already have local code execution on the host.
- Anthropic publishes the engineering post 'How We Contain Claude Across Products,' publicly documenting the VM-based isolation (Hyper-V/HCS on Windows), bubblewrap/seccomp guest-level layers, and domain-restricted egress proxy that Armadin's chain would later be shown to bypass.
- SiliconANGLE publishes coverage confirming Armadin's disclosure timeline and Anthropic's dispute of the finding's severity.
- Armadin publishes the full technical write-up, 'Exploiting Root Execution in Claude Cowork's Sandbox,' detailing the DLL sideloading, RPC spawn method, isResume parameter bypass, nsenter sandbox escape, allowedDomains egress-proxy bypass, and a live /etc/shadow exfiltration proof-of-concept via curl and base64 encoding.
- TL-2026-1115 threat hunt opened under the 'Public PoC available' criterion given the fully published, reproducible attack chain and absence of an assigned CVE.
- GBHackers and SC Media publish further technical breakdowns of the CoworkVMService RPC exploitation, the isResume/allowedDomains parameters, the sdk-daemon/useradd root cause, and the nsenter-based sandbox escape with /etc/shadow exfiltration.
- Cyber Security News publishes a technical analysis of the exploit chain, syndicating Armadin's findings to a wider security audience.
Sources cited for Claude Cowork Sandbox Escape
- Claude Cowork's Sandbox Vulnerability Allows Attackers to Run Arbitrary Commands as Root
- Armadin details full sandbox escape in Claude Cowork but Anthropic disputes risk
- Exploiting Root Execution in Claude Cowork's Sandbox
- Claude Cowork Sandbox Flaw Lets Attackers Execute Commands as Root in Hyper-V VM
- Researchers detail attack chain escaping Anthropic's Claude Cowork sandbox
- How we contain Claude across products
- Escaping the Sandbox: Jailbreaking Claude Cowork
- ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
- Anthropic Introduces Claude Cowork
Detection coverage for TL-2026-1115
As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1115 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.