CVE-2026-77179
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.
- Published Sep 15, 2026
- CVSS 9.4 critical
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
In the news
- ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats The Hacker News ·
- ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks The Hacker News ·
- Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files The Hacker News ·