Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Docker warned of CVE-2026-77179 in Docker Sandboxes for macOS: malicious code inside a virtual machine can escape the shared project folder and read or modify any host files with the privileges of the account that launched the VM. The issue is rated critical.
- Vulnerability CVE-2026-77179 rated critical
- Malicious code in VM escapes project folder
- Host file access uses user account privileges
- Docker disclosed the issue on September 15
Read next
Security