Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3444 articles · 168093 vulns · 36/41 feeds (7d)
← Back to list
8.7
CVE-2026-7574
anthropic · claude desktop cowork

Anthropic Claude Desktop Cowork VM Image Contents Not Validated Before Use

Description

Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1.1617.0, and v1.2278.0) validates only file presence and a version marker string before booting rootfs.img, but does not verify image content integrity at time-of-use. A local attacker with unprivileged code execution as the victim macOS user can modify the VM root filesystem image and have it trusted on subsequent Cowork VM boots, enabling persistent arbitrary code execution in the VM and access to host-mounted directories. The estimated CWE mapping is CWE-353 (Missing Support for Integrity Check).

Affected Products

VendorProductVersions
anthropicclaude desktop cowork1.1348.0

References

  • https://cfp.recon.cx/recon-2026/talk/DZUQYU/(related)
  • https://takeonme.org/gcves/GCVE-1337-2026-00000000000000000000000000000000000000000000000001110111111101011111111110000000000000000000000000000000000000000000000000000001010(third-party-advisory)

Related News (1 articles)

Tier C
VulDB4d ago
CVE-2026-7574 | Anthropic Claude Desktop Cowork up to 1.2278.0 VM Image rootfs.img integrity check
→ No new info (linked only)
CVSS 3.18.7 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
CISA KEV❌ No
Actively exploited❌ No
CWECWE-353
PublishedJun 23, 2026
Last enriched4d agov2
Trending Score19
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-54316EXP
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Trending: 23
PRE-CVE
Anthropic's Fable 5 Model Jailbroken
Trending: 10
MEDIUMCVE-2026-46406
@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
HIGHCVE-2026-40068
Claude Code arbitrary code execution via git worktree commondir trust dialog bypass
NONECVE-2026-35022EXP
Anthropic Claude Code & Agent SDK OS Command Injection via Authentication Helper

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 23, 2026
Discovered by ZDM
Jun 24, 2026
Updated: description
Jun 24, 2026

Version History

v2
Last enriched 4d ago
v2Tier C4d ago

Updated description for more technical detail and confirmed no exploit exists.

description
via VulDB
v14d ago

Initial creation