# Claude Cowork Sandbox Escape: RPC Parameter Bypass Enables Root Command Execution

> Security research firm Armadin publicly disclosed a two-stage exploit chain against Anthropic's Claude Cowork on Windows: DLL sideloading of a malicious USERENV.dll to gain code execution inside the signed claude.exe process, followed by an RPC parameter-validation bypass (isResume: true) against the CoworkVMService spawn method that returns a root shell inside the product's bubblewrap-isolated Linux VM, with a second allowedDomains wildcard bypass defeating the egress proxy. Anthropic disputes the finding as an in-scope security vulnerability because exploitation presupposes an attacker already has local code execution on the Windows host.

- **Published:** 2026-07-02T00:00:00Z
- **Last reviewed:** 2026-07-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1115
- **ID:** TL-2026-1115
- **Severity:** MEDIUM
- **Category:** VULNERABILITY
- **Status:** TRACKING
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Claude Cowork for Windows (packaged as Claude Desktop for Windows, observed at version 1.9255.2.0, installed under the WindowsApps MSIX path) sandboxes agent-executed code inside a Hyper-V Container System (HCS)-isolated Ubuntu Linux VM. Inside that VM, isolation is layered through bubblewrap namespaces, seccomp filtering, per-session unprivileged Linux users, and a domain-restricted egress (MITM) proxy. The host-to-guest control channel is an Authenticode-gated named-pipe RPC service, CoworkVMService, reachable at \\.\pipe\cowork-vm-service, using a simple [4-byte big-endian length][JSON payload] wire framing.

Armadin researcher Nick McClendon first achieved arbitrary code execution inside the legitimately Anthropic-signed claude.exe process via classic DLL search-order hijacking: claude.exe resolves USERENV.dll from its own application directory before falling back to the genuine System32 copy, so a malicious DLL exporting GetUserProfileDirectoryW and named USERENV.dll, dropped alongside claude.exe (found at C:\Program Files\WindowsApps\Claude_1.9255.2.0_x64__pzs8sxrjxfjjc\app\claude.exe), loads and executes inside the trusted, signed process without ever invalidating the running binary's own Authenticode signature.

From that foothold, the researcher used log analysis, JSON fuzzing, and parameter discovery to reverse-engineer the undocumented CoworkVMService RPC protocol, identifying methods including configure, startVM, isGuestConnected, and spawn. CoworkVMService gates pipe connections using WinVerifyTrust to require the connecting process be signed by "Anthropic, PBC" — but this only authenticates the calling binary's publisher, never authorizing or validating the contents of the RPC request itself. The spawn method exposes two undocumented parameters, isResume and allowedDomains. Normally isResume: false forces creation of a fresh unprivileged per-session Linux user for each command; setting isResume: true instead skips the existing-user validation path entirely, letting the daemon execute the requested command as any specified user — including root — with no authorization check. A crafted request such as {"name": "root", "isResume": true} returns an interactive shell with uid=0, full Linux capabilities, and an unconfined AppArmor profile.

From that root shell, still nominally confined by bubblewrap namespaces, the researcher used nsenter targeting PID 1 (nsenter --target 1 --mount --pid --uts --ipc --net) to join the host VM's mount, PID, UTS, IPC, and network namespaces, fully escaping the bwrap sandbox into the broader Hyper-V-isolated Ubuntu guest. A second, independent flaw in the same spawn method allows the allowedDomains parameter to override the VM's network egress allowlist on a per-command basis; while the default proxy configuration returns HTTP 403 for non-allowlisted domains, submitting "allowedDomains": ["*"] grants the sandboxed session unrestricted outbound network connectivity, defeating the domain-restricted egress proxy that is otherwise Cowork's primary control against data exfiltration and untrusted C2 callbacks from agent-executed code.

Claude Cowork itself launched as a research preview on 2026-01-12 as Anthropic's 'computer agent' for non-technical knowledge workers, followed by a wider enterprise rollout in February 2026 adding third-party connectors (Google Drive, Gmail, DocuSign, FactSet). The Windows sandbox architecture Armadin targeted is the same architecture Anthropic later described publicly in its 2026-05-25 engineering post 'How We Contain Claude Across Products,' which documents the VM-based isolation (Apple's Virtualization framework on macOS, HCS on Windows), the bubblewrap/seccomp guest-level layers, and the api.anthropic.com-scoped egress proxy — precisely the control layers Armadin's chain was built to defeat. Inside CoworkVMService, per-session unprivileged-user enforcement is implemented by a backend component the researcher identified as sdk-daemon, which normally invokes useradd to provision a fresh unprivileged Linux account for every non-resumed command; the isResume:true bypass skips this useradd-backed provisioning path entirely, which is the root cause enabling arbitrary-user (including root) command execution. To demonstrate real-world impact beyond a bare root shell, Armadin chained the nsenter host-namespace escape with a live data-exfiltration proof-of-concept: from the escaped VM, the researcher used curl to transmit the contents of /etc/shadow off the sandbox with base64 encoding applied to the payload, showing that both the credential-bearing shadow file and the exfiltration channel itself remained invisible to host-based endpoint defenses because all activity occurred inside the isolated Hyper-V guest rather than on the monitored Windows host.

Armadin reported the full chain to Anthropic on 2026-03-20 under responsible disclosure; Anthropic responded on 2026-03-24 declining to treat it as a qualifying security vulnerability, reasoning that the attack requires the attacker to already possess local code execution on the host — a precondition outside Cowork's stated threat model, which sandboxes agent-generated code rather than defending against an attacker who already owns the host OS. Armadin subsequently published the complete technical write-up and proof-of-concept publicly on 2026-07-01, triggering broad security-press coverage. No CVE has been assigned by MITRE/NVD and the issue does not appear in the CISA Known Exploited Vulnerabilities catalog; there is no evidence of in-the-wild exploitation — this is a disclosed, vendor-disputed, publicly-PoC'd design flaw in Cowork's Windows sandbox rather than an actively exploited campaign. For defenders, the practical exposure is that any local process capable of writing to the Cowork installation directory (e.g., malware already run via other means, a malicious insider, or a supply-chain-compromised auxiliary tool) can pivot local code execution into full root access and full sandbox/VM escape, and separately into unrestricted network egress and credential-file exfiltration from the sandboxed agent session — materially expanding the blast radius of any host that already has some form of local compromise.

## MITRE ATT&CK

- T1574 Hijack Execution Flow
- T1574 Hijack Execution Flow
- T1611 Escape to Host
- T1611 Escape to Host
- T1685 Disable or Modify Tools
- T1553 Subvert Trust Controls
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1518 Software Discovery
- T1057 Process Discovery
- T1068 Exploitation for Privilege Escalation
- T1090 Proxy
- T1005 Data from Local System
- T1567 Exfiltration Over Web Service
- T1587 Develop Capabilities
- T1003 OS Credential Dumping
- T1132 Data Encoding

## Sources

- [Claude Cowork's Sandbox Vulnerability Allows Attackers to Run Arbitrary Commands as Root](https://cybersecuritynews.com/claude-coworks-sandbox-vulnerability/)
- [Armadin details full sandbox escape in Claude Cowork but Anthropic disputes risk](https://siliconangle.com/2026/07/01/armadin-details-full-sandbox-escape-claude-cowork-anthropic-disputes-risk/)
- [Exploiting Root Execution in Claude Cowork's Sandbox](https://www.armadin.com/blog-posts/exploiting-root-execution-in-claude-coworks-sandbox)
- [Claude Cowork Sandbox Flaw Lets Attackers Execute Commands as Root in Hyper-V VM](https://gbhackers.com/claude-cowork-sandbox-flaw/)
- [Researchers detail attack chain escaping Anthropic's Claude Cowork sandbox](https://www.scworld.com/brief/researchers-detail-attack-chain-escaping-anthropics-claude-cowork-sandbox)
- [How we contain Claude across products](https://www.anthropic.com/engineering/how-we-contain-claude)
- [Escaping the Sandbox: Jailbreaking Claude Cowork](https://dev.to/aaron_walker_dc0d1194638f/escaping-the-sandbox-jailbreaking-claude-cowork-dbd)
- [ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories](https://thehackernews.com/2026/07/threatsday-ai-compute-hijacking-apple.html)
- [Anthropic Introduces Claude Cowork](https://aibusiness.com/agentic-ai/anthropic-introduces-claude-cowork)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1115
