Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Two arrested for Louvre stunt ‘for fun’ in Mona Lisa hall

    September 20, 2026

    Newegg Promo Codes and Coupons for September 2026

    September 20, 2026

    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

    September 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Two arrested for Louvre stunt ‘for fun’ in Mona Lisa hall
    • Newegg Promo Codes and Coupons for September 2026
    • Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
    • Treasury Sanctions Crypto Exchange Behind Iran’s Bitcoin Tolls on Hormuz Ships
    • Cultural treasures are being destroyed by war, and people want justice
    • Meta’s Muse is creepy, but maybe not for the reasons you think
    • CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
    • Gen Z are investing like Boomers
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 20
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 20, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 17, 2026Vulnerability / Artificial Intelligence

    Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15.

    The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions 0.28.0 up to but not including 0.42.0 on macOS, and was fixed in 0.42.0 on September 7.

    Docker Sandboxes runs each AI coding agent in its own small virtual machine with the project directory shared in. The code that could escape is whatever runs inside that machine, such as a coding agent that has been turned against its user, or anything malicious the agent installs and runs.

    Docker has not reported any exploitation. CISA’s added assessment on the CVE record lists exploitation as none, and the flaw is not in CISA’s Known Exploited Vulnerabilities catalog as of the catalog version released on September 16.

    The flaw needs malicious code inside the sandbox, and protecting the host from what an agent runs is what the sandbox is for. The agent installs packages and runs commands with sudo inside the virtual machine, and Docker’s isolation documentation says the hypervisor boundary “is the isolation control, not in-VM privilege separation.”

    The escape goes through the virtio-fs host server, the host side of the file sharing between the Mac and the virtual machine, which followed symlinks when it reopened a removed file from a stored path, Docker said.

    A guest, meaning whatever runs inside the virtual machine, could replace a parent directory with a symlink and then read or change files as the VMM user, the host account under which the virtual machine monitor runs, Docker said, “potentially leading to code execution on the host.”

    Cybersecurity

    Docker’s documentation has said since March that symlinks pointing outside the workspace, Docker’s term for the shared project directory, are not followed.

    The same release fixes a second flaw, CVE-2026-79994, rated High by Docker with a CVSS score of 8.7, in the relay that allows a sandbox to connect to Unix domain sockets within its authorized workspace.

    The relay checked that a socket path was inside the workspace, then reconnected using the path name. A guest that replaced a directory along that path with a symlink between the check and the connection could make the host connect to any AF_UNIX socket outside the workspace, Docker said, “exposing data or host-side capabilities provided by that socket.”

    That flaw affects versions 0.37.0 through 0.41.9, but not 0.42.0. Docker lists the first flaw as macOS-only but states no platform for it, whereas Docker Sandboxes runs on macOS, Windows, and Linux hosts. CISA’s assessment on its record also lists exploitation as none, and it is not in the KEV catalog either.

    Affected Versions and What to Install

    CVE Component Affected versions Platform Docker rating
    CVE-2026-77179 virtio-fs host server 0.28.0 up to but not including 0.42.0 macOS Critical, CVSS 9.4
    CVE-2026-79994 Guest-to-host Unix socket relay 0.37.0 up to but not including 0.42.0 None stated High, CVSS 8.7
    1. Update to 0.42.0 or later. As of September 17, the most recent release is 0.43.0, published on September 15.
    2. If you cannot update yet, use clone mode and avoid adding read-write host mounts. That is Docker’s advice for both flaws.

    By default, sbx run shares the current directory into the sandbox with read and write access. Clone mode works only when the project is a Git repository, and it is set when the sandbox is created, so an existing sandbox has to be removed and created again with –clone.

    Clone mode protects the repository from changes, not from reading. The repository is mounted read-only at /run/sandbox/source, and untracked files such as .env stay readable inside the sandbox, Docker’s documentation says.

    Cybersecurity

    Docker published the CVE records and the advisory on September 15, eight days after 0.42.0 shipped.

    The 0.42.0 release notes on GitHub and on Docker’s documentation site do not name either CVE as of September 17. Among routine fixes, they list one for “a sandboxed process could get the daemon to open a host D-Bus transport and execute an arbitrary command on the host.” Docker has not connected that fix to either CVE.

    The record for CVE-2026-79994 initially listed 0.41.0 as the first fixed version and linked to a 0.41.0 release page that does not exist. Docker corrected both to 0.42.0 about an hour after publishing the record on September 15.

    Docker credits Oren Yomtov of accomplish.ai with finding CVE-2026-77179 and Jurre van Bergen of ThreatNotify with finding CVE-2026-79994.

    In April, Cyera Research Labs described how a prompt-injected coding agent inside a Docker-based sandbox could be tricked into exploiting a separate Docker Engine flaw against its host.

    Code critical Docker Files Flaw guest Host lets macOS Malicious Modify Read Sandboxes
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

    SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

    Guest opinion: The debate over jail tablets is missing the point

    Identity Visibility in 2026: The Foundation of Identity Security

    Kalshi Files to Bring Perpetual Futures to US Stocks

    Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Two arrested for Louvre stunt ‘for fun’ in Mona Lisa hall

    September 20, 2026

    Newegg Promo Codes and Coupons for September 2026

    September 20, 2026

    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

    September 20, 2026

    Treasury Sanctions Crypto Exchange Behind Iran’s Bitcoin Tolls on Hormuz Ships

    September 20, 2026
    Latest Posts

    AIPAC Spending Dominates the Michigan Democratic Senate Primary

    August 5, 2026

    Labour members ‘have tougher view on welfare than you might think’, poll suggests | Labour

    August 5, 2026

    Palantir funnels earnings to US to avoid European taxes, report finds – POLITICO

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Two arrested for Louvre stunt ‘for fun’ in Mona Lisa hall

    September 20, 2026

    Newegg Promo Codes and Coupons for September 2026

    September 20, 2026

    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

    September 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.