NewsTradingSentimentCalendarCommunityBriefing
Tech

Docker Flaw Lets Malicious Code Access macOS Host Files

By Tech Desk · 2026-09-18 · 3 min read
A translucent glass box containing a small, glowing geometric shape, sitting on a wooden desk next to a laptop
Illustration: Tradingbird

A critical security flaw in Docker Sandboxes allows code running inside a virtual machine on macOS to escape its intended boundaries and access the host system.

Docker has disclosed a critical vulnerability in its Sandboxes product that affects users on macOS. The flaw, identified as CVE-2026-77179, allows malicious code running within a virtual machine to break out of its isolated environment. Once escaped, this code can read and modify files anywhere on the host operating system, effectively bypassing the security controls designed to keep the virtual environment separate from the user's computer.

According to a security announcement reported by The Hacker News, the issue arises from how the system handles file sharing between the Mac and the virtual machine. The vulnerability permits an attacker to manipulate symbolic links, creating a path that leads outside the designated project directory. This allows the malicious code to operate with the same permissions as the user account running the virtual machine, potentially leading to full control of the host system.

The flaw exploits file sharing mechanisms

The technical root of the problem lies in the virtio-fs host server, which manages file access between the Mac and the sandbox. Docker explained that the system followed symbolic links when reopening files from stored paths. An attacker inside the sandbox could replace a parent directory with a symlink, tricking the host into accessing files outside the intended workspace. This method allows the code to read or change sensitive data as the virtual machine monitor user.

This vulnerability is particularly concerning because Docker Sandboxes are designed to run AI coding agents in isolated environments. These agents often have broad permissions within the virtual machine, including the ability to install packages and execute commands with elevated privileges. If an agent is compromised or instructed to perform malicious actions, the sandbox is meant to contain the damage. However, this flaw undermines that containment by allowing the code to reach beyond the virtual boundary.

No active exploitation has been reported

Despite the critical severity rating of 9.4 on the Common Vulnerability Scoring System, there is currently no evidence that this flaw is being actively exploited in the wild. The Cybersecurity and Infrastructure Security Agency (CISA) has assessed the risk as having no known exploitation incidents. The vulnerability is also not listed in CISA’s Known Exploited Vulnerabilities catalog, which tracks flaws that are currently being used by attackers.

Docker addressed the issue in version 0.42.0, released on September 7. The company has not reported any cases of malicious use, but the potential impact remains significant for users who rely on the sandbox for running untrusted or experimental code. The fix ensures that symbolic links pointing outside the shared workspace are no longer followed, closing the escape route for malicious code.

Users should update to the latest version

Docker strongly recommends that all users update their Docker Sandboxes to version 0.42.0 or later immediately. The most recent release, version 0.43.0, was published on September 15 and includes the necessary security patches. For those unable to update right away, Docker suggests using clone mode and avoiding read-write host mounts as a temporary mitigation. However, this workaround has limitations and does not provide the same level of security as the official patch.

Clone mode works by mounting the project repository as read-only, which prevents changes but does not block reading of certain files. Untracked files, such as environment configuration files, may still be accessible to the sandbox. Therefore, updating to the fixed version is the most reliable way to protect against this vulnerability. Users should verify their current version and apply the update as soon as possible to maintain the integrity of their systems.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories
  • A sleek electric vehicle parked on a coastal road with a charging cable connected to a port
    Illustration: Tradingbird

    BYD's Global Push Complicates Tesla's Market Position

    BYD has posted record monthly sales, driven largely by a massive surge in overseas markets. This shift signals a direct collision with Tesla on international soil, changing the competitive landscape for both EV giants.

    2026-09-18
  • A digital shield protecting a network of interconnected nodes
    Illustration: Tradingbird

    AI Agents Force Stricter Data Controls in Business

    As AI systems move from assisting employees to executing tasks, businesses face a new challenge: ensuring that automated actions are traceable and accurate, especially in regulated industries like finance.

    2026-09-18
  • A high-performance gaming computer setup with a dual-monitor arrangement and an ergonomic chair in a modern hotel room
    Illustration: Tradingbird

    Nhow Hotels Add High-Performance Gaming Suites to European Locations

    Minor Hotels is expanding a pilot program that places professional-grade gaming hardware inside standard hotel rooms, targeting travelers who want to play without leaving their accommodation.

    2026-09-18