Skip to content
The Injection_
LIVE
LIVElast sweep UTCnext in--:--:--

[ RSS ][ JSON ][ llms.txt ]

Claude Desktop for macOS: Cowork files could run commands on open

A file type macOS runs on open was missing from Claude Desktop's blocklist, so agent-written files could execute.

· Anthropic · Research by Vladimir Tokarev (Cyera Research), Anthropic security team

Anthropic
HIGHVulnerability

Claude Desktop for macOS before 1.15962.0 could run commands on the host when a user opened a malicious file from a Cowork folder, because its blocklist of executable file types was incomplete. Anthropic rated it CVSS 4.0 8.5.

01What happened

Anthropic published an advisory on September 25, 2026 for Claude Desktop on macOS. A file placed in a Cowork shared folder by a compromised or prompt-injected agent could run commands on the Mac if the user opened it from Claude Desktop. Anthropic found the issue internally, and Vladimir Tokarev of Cyera Research reported it independently.

02How it works

Claude Desktop blocks file types that execute when opened, but the list left out one type that macOS runs on open (CWE-184). Releases before 1.11847.5 also shipped a Cowork VM image whose guest Linux kernel was affected by CVE-2026-43284, which the advisory says could let elevated code inside the VM trigger the file open with no user action.

03Who is affected

Claude Desktop for macOS from 1.1.3918 up to but not including 1.15962.0. Auto-update already delivers the fix.

04What to do

Make sure managed or manually updated Macs run Claude Desktop 1.15962.0 or later, and treat files an agent writes into Cowork folders as untrusted.

Questions people ask

Which Claude Desktop version fixes the Cowork file execution bug?
Claude Desktop 1.15962.0 fixes the Cowork file execution bug on macOS, according to Anthropic's advisory GHSA-v234-4jrq-mgg6. Versions from 1.1.3918 up to but not including 1.15962.0 are affected. Auto-update already delivers the fix, so the main risk is on Macs where updates are managed centrally or turned off.
Does the Claude Desktop Cowork bug need user interaction?
The Claude Desktop Cowork bug normally needs the user to open a malicious file from Claude Desktop, and Anthropic's CVSS 4.0 vector marks user interaction as passive. The advisory adds that on releases before 1.11847.5, a Cowork VM kernel flaw, CVE-2026-43284, could let elevated code inside the VM trigger the file open with no user interaction.
Is Claude Desktop on Windows affected by GHSA-v234-4jrq-mgg6?
Anthropic's advisory GHSA-v234-4jrq-mgg6 describes the issue as affecting Claude Desktop on macOS, where a file type that the operating system runs on open was missing from the blocklist. The advisory does not list Windows as affected. Teams running Claude Desktop on any platform should still keep it on the latest version.

Sources 2 links, all fetched

  1. 1github.comAnthropic Advisory
  2. 2github.comAll Anthropic Advisories