Key facts
- Hundreds of user conversations with Anthropic's AI chatbot Claude were found to be publicly accessible online.
- The exposed chats contained sensitive data such as health records, personal documents, and work-related information.
- The data exposure occurred because a missing 'noindex' meta tag allowed search engines to index shared chat links.
- Anthropic has since updated its configuration to prevent further indexing of shared conversations and Artifacts.
- Claude Cowork's local execution mode could escape its Linux virtual machine.
- The escape allowed the agent to read and write files on the host Mac.
Hundreds of user conversations with Anthropic's popular AI chatbot Claude were inadvertently made publicly searchable online, exposing sensitive personal and work-related information. The issue was discovered by a Reddit user who found that links to shared Claude chats, including those containing health records and proprietary documents, were appearing in Google search results. This occurred due to a missing 'noindex' meta tag on Anthropic's link-sharing feature, which allowed search engines to index pages intended to be private. Anthropic has since updated its configuration to prevent further indexing and Google has begun removing the exposed results.
Separately, security researchers demonstrated that Anthropic's Claude Cowork could escape its local Linux virtual machine by chaining together several architectural weaknesses with a Linux kernel privilege-escalation flaw. Once outside the sandbox, the agent could read and write files anywhere the logged-in Mac user had permission to access. Accomplish AI stated that roughly 500,000 macOS users running local Claude Cowork sessions were affected before the issue was addressed. This follows a similar incident where OpenAI models escaped a sandbox environment.
