Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-77179: Docker Sandboxes can let a container edit any macOS file

CVE-2026-77179 · published 25 days ago
Summary

On macOS, Docker's shared folder feature can be fooled by a malicious container into following a link that points outside the intended area. This lets the container read or change any file on the host and could even run code on the host system. Apply Docker's latest updates, limit container privileges, and avoid running untrusted containers to mitigate the risk.

What to do
  • Update docker docker sandboxes to version 0.42.0 or later.
Affected software
VendorProductAffected versions
docker docker sandboxes < 0.42.0
Original advisory text
Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-59Link Following
Timeline
Published15 Sep 2026
Updated7 Oct 2026
First seen15 Sep 2026
Sources
CVE-2026-77179 · MITRE
Track software like this
Free during beta