What is Claude vm_bundles, and why is it so big?
- Location
~/Library/ Application Support/ Claude/ vm_bundles - Safe to delete?
- Partly, with care The VM re-downloads when needed. Leave the rest of the Claude folder alone.
vm_bundles is where the Claude desktop app keeps the Linux virtual machine that Cowork uses to run code on your Mac. You can delete it once Claude is quit, and Claude downloads it again when a local Cowork task needs it. Leave the rest of the Claude folder alone. It holds your sign-in, settings and local Cowork history.
What is vm_bundles?
Cowork is the part of Claude that takes on longer jobs, working with files in folders you connect and running code. In a local Cowork session in the desktop app, Anthropic says Claude’s work happens on your computer and the code runs in an isolated virtual machine. On a Mac, that VM runs on Apple’s Virtualization framework.
The vm_bundles folder holds that VM. Inside you’ll usually find one item, claudevm.bundle, which contains:
rootfs.img, the VM’s main disk. It’s a full Ubuntu Linux system with tools like Chromium and LibreOffice preinstalled.sessiondata.img, a smaller disk where the sandbox keeps a working folder for each session.- Compressed
.zstcopies of the disk and boot files, a Linux kernel (vmlinuzandinitrd), and a few tiny boot and ID files, as the listing in this bug report shows.
Right next to it you may see claude-code-vm. It holds the Cowork runtime, a Linux build of Claude Code that runs inside the VM, in a subfolder named for its version (bug report). Don’t confuse it with claude-code (no “-vm”), which is the Mac copy of Claude Code the desktop app uses.
Plain chats don’t use the VM, and neither does Claude Code in Terminal, according to this teardown. The Claude app’s web caches sit in the same parent folder and are a separate cleanup. The AI app storage guide covers those. Chrome stores its own on-device AI model too, in OptGuideOnDeviceModel.
Is it safe to delete?
Yes for vm_bundles itself, with two costs. Claude has to download and rebuild the VM before your next local Cowork task, and anything left inside an unfinished task’s sandbox goes with it.
- rootfs.img, the compressed copies and the boot files: safe. They’re a stock system image, and Claude fetches a fresh copy when it needs one, as this bug report on Anthropic’s GitHub describes.
- sessiondata.img: scratch space. Files Claude saves into a folder you connected live on your Mac, outside the VM disk, shared into the VM. One person who deleted it reported no loss of projects or Cowork history. If a task made something you want and it only exists inside the sandbox, save it to a connected folder first.
The parent folder, ~/Library/Application Support/Claude, is a different story. It mixes rebuildable files with your data. It holds your sign-in, your app settings, and claude_desktop_config.json, which is where your MCP server setup lives. Anthropic also says local Cowork sessions keep conversation history on your computer. That history sits next to vm_bundles in local-agent-mode-sessions, per one bug report. Delete the whole Claude folder and you lose all of that.
Why it gets so big
The VM’s disk holds a whole operating system. Bug reports on Anthropic’s GitHub say the bundle can reach about 10 GB, and one measured it at 11.2 GB because the compressed download stayed on disk after Claude unpacked it.
The disk file doesn’t shrink on its own, either. Deleting files inside the VM doesn’t give your Mac that space back, and Claude doesn’t compact the disk afterward, according to this open issue.
How to clear it yourself
- Check the size (optional). In Finder, select the folder and choose File > Get Info. Or run this in Terminal, which only reads:
du -sh ~/Library/Application\ Support/Claude/vm_bundles - Save any work from an unfinished Cowork task into a folder on your Mac.
- Quit Claude. Choose Claude > Quit Claude or press Command-Q. Closing the window isn’t enough. Then open Activity Monitor and make sure nothing named Claude is still running. If something is, select it, click the Stop button, then click Quit.
- Open the folder. In Finder, choose Go > Go to Folder, paste
~/Library/Application Support/Claude/and press Return. - Drag
vm_bundlesto the Trash. You can dragclaude-code-vmalong with it. Claude should set it up again the next time Cowork starts. - Leave everything else in that folder alone. That includes
claude-code,claude_desktop_config.json,local-agent-mode-sessionsand the files that keep you signed in. - Open Claude and check it. Your chats and settings should look the same. Then empty the Trash. Your Mac doesn’t free the space until you do, but until then you have a way back. More on that in why Trash first.
The next time you start a local Cowork task, expect a wait while Claude downloads and rebuilds the VM.
What SpaceUp Mac does with it
SpaceUp Mac lists vm_bundles and claude-code-vm together as “Claude Cowork VM images” in the Clean tab, and in Dev Mode when SpaceUp Mac detects developer or AI tools. It’s marked Review and stays unticked until you choose it. If you tick it, the app deletes the folders’ contents directly instead of moving them to the Trash. If Claude is open when you clean, it skips this item and asks you to quit Claude and clean again. Deep Scan lists the whole Claude folder as “App / SDK data · review” with a note that it mixes your sign-in and settings with the VM images, and asks you to confirm before moving that folder to the Trash (how cleaning works).
Common questions
Will deleting vm_bundles delete my Claude chats?
No. Your regular chats live in your Claude account, not in this folder, and local Cowork history lives in a separate folder next to vm_bundles, per this report. Deleting the whole Claude folder is what puts local history at risk.
Why did it come back?
Claude rebuilds the VM when it needs it. One user reported the bundle was back to full size the next day. If you use local Cowork, deleting it only buys you space until the next task.
Can I turn it off if I never use Cowork?
Anthropic doesn’t document a switch for individual users. For company-managed Macs on Team and Enterprise plans, it lists an admin policy, secureVmFeaturesEnabled, that turns off Cowork access (enterprise configuration), but it doesn’t say whether that also stops the VM download. An Anthropic engineer said on Hacker News the team had ideas for more control for people who don’t use Cowork.
Why does Claude need a VM at all?
It keeps the code Claude writes away from your Mac’s own system. Anthropic says shell commands and code run inside the VM, while reading and writing files in your connected folders happens on the Mac itself.