Symlink Vulnerability in Docker Sandboxes on macOS
CVE-2026-77179
Key Information:
- Vendor
Docker
- Status
- Vendor
- CVE Published:
- 15 September 2026
Badges
What is CVE-2026-77179?
CVE-2026-77179 is a vulnerability found in the Docker Sandboxes specifically on macOS systems. Docker, a popular platform for developing, shipping, and running applications in containers, utilizes a mechanism known as virtio-fs for file sharing between the host and containers. This vulnerability arises from the improper handling of symlinks by the virtio-fs host server when reopening files that have been unlinked. A malicious actor could exploit this flaw by crafting a symlink in a parent directory, enabling them to escape the confines of the shared workspace. This could potentially lead to unauthorized access to modify or read arbitrary files on the host machine with the privileges of the Virtual Machine Monitor (VMM) user. Since Docker is widely used in development and production environments, this vulnerability poses a serious risk to organizations that rely on containerized applications.
Potential impact of CVE-2026-77179
-
Unauthorized Access to Host Files: The ability for a malicious guest within a Docker container to access host files can lead to significant security breaches. Sensitive data, configuration files, and other critical system components could be exposed or altered.
-
Host Code Execution: By exploiting this vulnerability, an attacker could potentially execute arbitrary code on the host operating system. This escalates the risk of compromising the entire system, leading to a loss of integrity and availability of services.
-
Increased Attack Surface for Ransomware and Other Threats: The exploitation of this vulnerability could set the stage for further attacks, including ransomware deployment, as the compromised host may serve as a launch pad for spreading malware to other systems within the network.
Affected Version(s)
Docker Sandboxes MacOS 0.28.0 < 0.42.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Docker Fixes Critical Sandboxes Flaw That Could Expose Host Files - IT Security News
Docker has patched two vulnerabilities in Docker Sandboxes that could allow malicious code running inside an isolated sandbox to cross its intended workspace boundary and interact with resources on the host...
2 weeks ago
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Docker Sandboxes flaws can expose host files or Unix sockets outside the workspace; both were fixed in 0.42.0, with no exploitation reported
3 weeks ago
Critical Docker Sandbox Vulnerabilities Enable Malicious Guests to Escape Isolated microVM Workspaces
Docker patched two serious Sandbox vulnerabilities that could let malicious guest workloads escape their isolated workspace and access sensitive host resources.
3 weeks ago

References
CVSS V4
Timeline
- π₯
Vulnerability reached the number 1 worldwide trending spot
- π
Vulnerability started trending
- π‘
Public PoC available
- πΎ
Exploit known to exist
- π°
First article discovered by Cybersecuritynews
Vulnerability published
Vulnerability Reserved
