Symlink Vulnerability in Docker Sandboxes on macOS
CVE-2026-77179
9.4CRITICAL
What is CVE-2026-77179?
A vulnerability exists in the virtio-fs host server used by Docker Sandboxes on macOS, where improper symlink handling when reopening unlinked files can lead to unauthorized access. An attacker can manipulate the environment by replacing a parent directory with a symlink, allowing them to escape from the shared workspace. This misuse may enable the malicious guest to read or modify arbitrary files on the host system as the Virtual Machine Monitor (VMM) user, thus posing a significant security risk.
Affected Version(s)
Docker Sandboxes MacOS 0.28.0 < 0.42.0
