Symlink Vulnerability in Docker Sandboxes on macOS
CVE-2026-77179

9.4CRITICAL

Key Information:

Vendor

Docker

Vendor
CVE Published:
15 September 2026

What is CVE-2026-77179?

A vulnerability exists in the virtio-fs host server used by Docker Sandboxes on macOS, where improper symlink handling when reopening unlinked files can lead to unauthorized access. An attacker can manipulate the environment by replacing a parent directory with a symlink, allowing them to escape from the shared workspace. This misuse may enable the malicious guest to read or modify arbitrary files on the host system as the Virtual Machine Monitor (VMM) user, thus posing a significant security risk.

Affected Version(s)

Docker Sandboxes MacOS 0.28.0 < 0.42.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Oren Yomtov of accomplish.ai
.