If your team uses Claude Desktop Cowork on macOS, update to version 1.15962.0 or later now. An Anthropic advisory published on 25 September 2026 says that a malicious file from a shared Cowork folder can run commands on a Mac when a user opens it from ClaudeClaude ProThe paid subscription for the Claude AI assistant from Anthropic. It unlocks connectors to outside tools.Open the glossary Desktop.
Cowork is a Claude Desktop feature that runs an agentAI agentAn AI program that performs work steps by itself, for example reading a message, drafting a reply, and recording the result.Open the glossary in a virtual machine and gives the agent a shared folder to exchange files with the host. This boundary matters because folder content can come from untrusted documents, websites, or prompts.
The primary source is Anthropic advisory GHSA-v234-4jrq-mgg6. This article does not claim that every Cowork file is malicious or that exploitation occurred on your systems.
What changed in Claude Desktop 1.15962.0?
Claude Desktop keeps a list of file types that can execute code when opened. The application blocks those types from opening directly from a shared Cowork folder. This stops a file written inside the sandbox from becoming host code execution without user intent.
According to Anthropic's 25 September 2026 advisory, the list omitted one file type that macOS executes when opened. A compromised or prompt-injected agent could place that file in a Cowork folder. If a user opened it from Claude Desktop, the file could run commands on the Mac.
Version 1.15962.0 adds the missing type and related types to the block list. Anthropic rates the advisory High. The fix concerns Claude Desktop for macOS. It is not a vulnerability in the Claude model, Claude APIAPIThe official door 2 systems use to exchange data, without anybody copying it by hand.Open the glossary, or a normal Claude Code terminal session.
| Condition | Operational risk | Action |
|---|---|---|
| Claude Desktop macOS before 1.15962.0 with Cowork | A file from Cowork can bypass the block list when a user opens it. | Update before opening new Cowork files. |
| Claude Desktop 1.15962.0 or later | The reported file type and related types are on the block list. | Verify the version and keep file review rules. |
| Standard auto-update | Anthropic says the fix has been delivered. | Still verify the version. |
| Manual or managed update | A device can remain on a vulnerable build. | Deploy the latest version through device management. |
Do you need to upgrade now?
Yes, if your organization uses Cowork on macOS. The vulnerability crosses the sandbox boundary through a file-open action. Commands can run with the privileges of the user who opened the file.
If you do not use Cowork, the attack path does not directly apply. An update is still reasonable because version 1.15962.0 includes the wider block list. Teams with managed updates must prioritize device inventory because Anthropic advises manual and managed-update users to install the latest version.
The advisory also describes a combined condition with CVE-2026-43284 in the Linux kernel of an old Cowork VM image. Claude Desktop 1.11847.5, released on 9 June 2026, updated the VM image to a patched kernel. Version 1.15962.0 or later contains both changes.
How do you update safely?
- Stop opening new files from Cowork folders. Wait until you check the application version.
- Record the installed version. Confirm that every Mac runs Claude Desktop 1.15962.0 or later.
- Use the official update channel. For managed devices, use the organization's deployment system.
- Restart the application. Check the version again to confirm the active binary changed.
- Review unopened Cowork files. Check the source, real extension, and business need.
- Limit user account impact. Do not use an administrator account for daily work unless required.
- Record exceptions. Devices that cannot update should not use Cowork until remediation is complete.
Apply the test principles in our chaos engineering guide for AI coding agents. For many coding-agent sessions, separate accounts, work folders, and permissions as described in our Claude Code Agent Teams guide.
What can fail if the team does not upgrade?
The application does not have to fail immediately. The security control can look normal until a user opens a specific file from a Cowork folder. Without the update, the team still depends on a block list that omits the reported macOS file type.
A behavior rule helps, but it is not equal to a patch. Prompt injection can give a file a convincing name and context. The patch reduces the technical path. File-review policy reduces the remaining risk.
Questions and answers
Is this a vulnerability in the Claude model?
No. The advisory describes file handling in Claude Desktop Cowork for macOS.
Can the file run without being opened?
For the file-handling issue by itself, a user must open the file. No-interaction execution requires the combined old VM condition described in the advisory.
What is the minimum fixed version?
Anthropic says Claude Desktop 1.15962.0 adds the missing file type and related types to the block list.
Do auto-update users need to act?
Anthropic says standard auto-update users have received the fixes. You should still verify the version.
Does this advisory affect Windows?
The advisory specifically describes a file type that macOS executes. Do not extend the claim to Windows without a separate advisory.
Operational conclusion
Inventory Claude Desktop on macOS, stop opening Cowork files on old versions, and update all devices to 1.15962.0 or later. Then keep source review and non-administrator accounts. A block-list patch does not replace access control and file verification.



