• Login
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
No Result
View All Result

Home / Security / Docker Sandboxes flaw lets guest code read macOS host files

Docker Sandboxes flaw lets guest code read macOS host files

byLotfi Ben Taleb
September 18, 2026
in Security
Reading Time: 2 mins read
MacBook, wireless keyboard, trackpad, and a ceramic mug on a wooden desk
Share on Facebook
Share on Twitter

Malicious code running inside a Docker Sandboxes virtual machine on macOS can break out of the single project folder shared into it and reach files anywhere else on the host, Docker said in a security announcement on 15 September. The docker sandboxes vulnerability, tracked as CVE-2026-77179 and rated Critical, lets a guest process read or overwrite host files with the same rights as whichever account launched the virtual machine.

Docker Sandboxes is built to run project code inside a VM rather than directly on the Mac, with only one folder, the project directory a developer explicitly shares in, visible to that VM. Everything else on the host is meant to stay off-limits. CVE-2026-77179 removes that limit: guest code can step outside the shared folder and reach the rest of the filesystem, which is precisely the access the sandbox exists to deny.

The value of that model is that a developer can point Sandboxes at a folder containing code from a source they only partly trust, a dependency, a pull request, a generated script, without granting it any reach into the rest of the machine. That promise is what CVE-2026-77179 undermines: the one thing a developer explicitly did not share becomes reachable anyway.

Why the Docker Sandboxes vulnerability breaks host isolation

Most container escapes involve breaking out of namespace or cgroup restrictions on a shared kernel, a narrower barrier than a full virtual machine. Docker Sandboxes uses an actual VM boundary, which is normally the stronger of the two: a process inside the VM is supposed to have no direct path to the host’s files at all, let alone the host user’s own files. A flaw that crosses a VM boundary rather than a container boundary is why Docker rated this Critical instead of treating it as a narrower information leak.

The escape does not require root or any stolen credential. It runs with the rights of whichever account started the virtual machine, and on a typical single-user Mac that is the same account that owns the home directory. Guest code that finds the way out of the shared folder is not landing in some restricted corner of the disk: it inherits the same read and write access the developer already has, covering documents, browser profiles, SSH keys and anything else that account can touch.

What it means for Docker Sandboxes users on macOS

Anyone using Docker Sandboxes to run code they do not fully trust should treat that isolation as broken until Docker names a fixed build. Docker’s announcement on 15 September does not state which version resolves CVE-2026-77179, so the safest position for now is to assume the current release is still exposed and avoid pointing Sandboxes at anything untrusted in the meantime.

The flaw also has a public record at CVE-2026-77179 on the National Vulnerability Database, separate from Docker’s own write-up. It is worth checking directly: NVD entries get updated as vendors narrow affected version ranges or publish fixes, and that update will show up there before it necessarily reaches a summary of the original advisory.

Watch that record, and Docker’s own advisory, for the specific version that closes CVE-2026-77179. Until one is named, the practical fix is to keep untrusted code out of Docker Sandboxes on macOS entirely.

Tags: macosopen-sourcevulnerability
Previous Post

Intel reportedly prepping 8P+8E Raptor Lake Next chip

Next Post

Gyazo breach exposes 23.62 million user records

Related Posts

Tangled colored network patch cables running into a server rack panel
Security

Citrix confirms two NetScaler zero-days under active attack

September 28, 2026
Rows of blue-lit server hard drive caddies in a data center rack
Security

ShinyHunters bypass WAFs to exploit Oracle PeopleSoft flaw

September 27, 2026
Rendered illustration of a data center corridor lined with server racks showing blue status lights
Security

WSO2 and Adobe Commerce flaws land on CISA’s exploited list

September 26, 2026
0 0 votes
Article Rating
Subscribe
Notify of
0 Comments

Popular News

Three Samsung phone backs side by side, green with many cameras, purple and cream with three cameras

Galaxy S27 renders show a design split from the Ultra

October 1, 2026
Close-up of an iPhone's glass back and dual rear camera lenses lit from above

iPhone Duo 3D model lets you open the hinge before launch

September 20, 2026
A Radeon graphics card installed in a PC case, lit by green and blue ambient light

Modders get DLSS 5 running on AMD’s RDNA 4 GPUs

September 7, 2026
Close-up of a GeForce RTX graphics card installed in a PC case with a blurred power cable bundle

DLSS 5 mods expose RTX 5090’s power connector limit

September 27, 2026
Next Post
Hands on a silver laptop trackpad and keyboard, screen showing a grid of photo thumbnails

Gyazo breach exposes 23.62 million user records

Technology for enthusiasts and gamers. Hardware, gaming and the software in between, with the spec sheets read properly and the marketing taken back out.

Categories

Categories

  • AI
  • Gadgets
  • Gaming
  • Hardware
  • Policy
  • Security
  • Software
Site Links
  • Latest
  • About
  • Contact
About
  • How We Work
  • Privacy Policy

© 2026 teqpost. All rights reserved.

  • Privacy Policy
  • Contact

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply