Local Privilege Escalation in Claude Desktop App by Anthropic
CVE-2026-44470
8.5HIGH
What is CVE-2026-44470?
The Claude Desktop app prior to version 1.3834.0 contains a vulnerability in the CoworkVMService component, which runs with SYSTEM privileges. It lacks proper validation of the VM bundle directory, allowing a local non-elevated user to craft a directory junction that redirects file creation to an attacker-controlled location. This flaw enables the elevation of privileges, granting unauthorized access to system resources and potentially leading to further exploitation. Users are advised to update to version 1.3834.0 or later to mitigate this risk.
Affected Version(s)
claude-code < 1.3834.0
