Name: Towards AI Legal Name: Towards AI, Inc. Description: Towards AI is the world's leading artificial intelligence (AI) and technology publication. Read by thought-leaders and decision-makers around the world. Phone Number: +1-650-246-9381 Email: pub@towardsai.net
228 Park Avenue South New York, NY 10003 United States
Website: Publisher: https://towardsai.net/#publisher Diversity Policy: https://towardsai.net/about Ethics Policy: https://towardsai.net/about Masthead: https://towardsai.net/about
Name: Towards AI Legal Name: Towards AI, Inc. Description: Towards AI is the world's leading artificial intelligence (AI) and technology publication. Founders: Roberto Iriondo, , Job Title: Co-founder and Advisor Works for: Towards AI, Inc. Follow Roberto: X, LinkedIn, GitHub, Google Scholar, Towards AI Profile, Medium, ML@CMU, FreeCodeCamp, Crunchbase, Bloomberg, Roberto Iriondo, Generative AI Lab, Generative AI Lab VeloxTrend Ultrarix Capital Partners Denis Piffaretti, Job Title: Co-founder Works for: Towards AI, Inc. Louie Peters, Job Title: Co-founder Works for: Towards AI, Inc. Louis-François Bouchard, Job Title: Co-founder Works for: Towards AI, Inc. Cover:
Towards AI Cover
Logo:
Towards AI Logo
Areas Served: Worldwide Alternate Name: Towards AI, Inc. Alternate Name: Towards AI Co. Alternate Name: towards ai Alternate Name: towardsai Alternate Name: towards.ai Alternate Name: tai Alternate Name: toward ai Alternate Name: toward.ai Alternate Name: Towards AI, Inc. Alternate Name: towardsai.net Alternate Name: pub.towardsai.net
5 stars – based on 497 reviews

Frequently Used, Contextual References

TODO: Remember to copy unique IDs whenever it needs used. i.e., URL: 304b2e42315e

Resources

Free: 6-day Agentic AI Engineering Email Guide.
Learnings from Towards AI's hands-on work with real clients.
Claude Code Has More Control Over Your PC Than You Think
Artificial Intelligence   Latest   Machine Learning

Claude Code Has More Control Over Your PC Than You Think

Last Updated on September 22, 2026 by Editorial Team

Author(s): AI Rabbit

Originally published on Towards AI.

Claude Code Has More Control Over Your PC Than You Think

We recently heard about the massive incidents at OpenAI where agents broke out of the sandbox environment and broke into Hugging Face (and later even started hacking their own environment at OpenAI). And Claude is no different — it has had its own scandals and will probably continue to have them.

Claude Code Has More Control Over Your PC Than You Think

The author argues that Claude Code’s security model is fundamentally risky because it defaults to the permissions of the user running it and allows editing its own configuration. This means the typical “prompt-based” restrictions and application-level permission checks can be bypassed if the model decides to cheat or exploit alternate binaries that achieve the same capabilities (e.g., using Appium/Accessibility rather than blocked commands like osascript). The piece describes a real macOS review where automation tools captured unrelated windows without an appropriate prompt due to inherited OS permissions, then summarizes why editing the settings “rulebook” can undermine enforcement even if the harness keeps checks. The conclusion is a call to “start thinking OS”: enforce restrictions at the OS level using sandboxing/containers or VM isolation, avoid inherited GUI-control permissions by revoking Accessibility and Screen Recording for the terminal, run the agent under a separate user, make the settings rulebook immutable, and keep approvals interactive to reduce rule-based bypass risk.

Read the full blog for free on Medium.

Join thousands of data leaders on the AI newsletter. Join over 80,000 subscribers and keep up to date with the latest developments in AI. From research to projects and ideas. If you are building an AI startup, an AI-related product, or a service, we invite you to consider becoming a sponsor.

Published via Towards AI


Towards AI Academy

We Build Enterprise-Grade AI. We'll Teach You to Master It Too.

15 engineers. 100,000+ students. Towards AI Academy teaches what actually survives production.

Start free — no commitment:

→ 6-Day Agentic AI Engineering Email Guide — one practical lesson per day

→ Agents Architecture Cheatsheet — 3 years of architecture decisions in 6 pages

Our courses:

→ AI Engineering Certification — 90+ lessons from project selection to deployed product. The most comprehensive practical LLM course out there.

→ Agent Engineering Course — Hands on with production agent architectures, memory, routing, and eval frameworks — built from real enterprise engagements.

→ AI for Work — Understand, evaluate, and apply AI for complex work tasks.

Note: Article content contains the views of the contributing authors and not Towards AI.