What happened
Security researchers at Accomplish AI disclosed a vulnerability in Anthropic's Claude Cowork that allows an AI agent to break out of its designated Linux virtual machine and read or write files anywhere on the host Mac system — putting roughly 500,000 macOS users at potential risk. In a separate development, LG Electronics USA announced it will suspend smart TV applications on its webOS platform that quietly enlist televisions as residential proxy nodes. The action follows research showing that more than 42 percent of apps in LG's webOS store were routing internet traffic through users' home connections on behalf of unknown third parties.
Why it matters for your business
The Claude Cowork flaw is a concrete reminder that AI coding and productivity agents operate with real system-level access, and that the sandboxing meant to contain them is not infallible — any organization deploying such tools on employee machines should verify isolation controls and limit agent file-system permissions until a patch is confirmed. The LG smart TV situation illustrates a less obvious attack surface: consumer hardware sitting on corporate or home-office networks can become an unwitting relay for malicious traffic, complicating threat attribution and potentially violating acceptable-use or data-handling policies. Operations and IT leaders should audit which networked devices — including smart TVs in conference rooms or executive suites — are connected to business infrastructure, and treat them as potential exposure points rather than inert appliances.
What to watch next
Anthropic has not yet publicly detailed a patch timeline for the Claude Cowork vulnerability, so enterprise buyers should monitor the company's security advisories closely and consider whether to pause or restrict agent deployments in the interim. On the smart TV front, LG's enforcement actions will test how quickly third-party developers comply and whether other smart appliance platforms — Roku, Samsung Tizen, and Amazon Fire TV among them — face pressure to conduct similar audits. Regulators in the EU and US have shown increasing appetite for holding hardware makers accountable for third-party software distributed through their ecosystems, making this a policy story as much as a technical one.
