By weakness (CWE)
CWE-353: related vulnerabilities
CVEs classified under CWE-353. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
1 published vulnerability
- CVE-2026-7574HIGH 8.7
Claude Desktop's Cowork VM image loading mechanism performs a lightweight validation check—confirming the file exists and contains an expected version marker—but stops short of verifying that the image contents remain unmodified. An attacker who gains unprivileged code execution within the macOS user's session can tamper with the VM root filesystem image and cause it to be trusted and booted on the next Cowork VM launch. This allows persistent code execution inside the virtualized environment and potentially compromises any directories mounted from the host.