Executive brief
Claude Code is a development assistant that runs code in a sandboxed environment to protect the host system. A flaw in the sandbox's file protection allowed malicious code to create and modify a settings configuration file, injecting persistent hooks that execute with full system privileges when the application restarts. This enables complete compromise of the user's system and access to all their data.
Technical details
The vulnerability is a sandbox escape caused by improper file protection in bubblewrap's mount configuration. While the .claude/settings.local.json file was explicitly protected with read-only constraints, the .claude/settings.json file was not protected if it did not exist at startup—despite the parent directory being mounted as writable. Malicious code running inside the sandbox could create settings.json and inject persistent hooks (e.g., SessionStart commands) that would execute with host privileges upon application restart. The attack requires the attacker to first achieve code execution within the sandbox (via another vulnerability or malicious extension), but no additional user interaction is needed after that point. The vulnerability affects Claude Code versions prior to 2.1.2, which has been patched.
Affected products
- Anthropic Claude Code < 2.1.2
Timeline
- 2026-02-06: disclosed
- 2026-02-06: patched: Version 2.1.2 released