← All briefs
Brief·2 sources18 Sept 2026

CVE-2026-77179 Enables Docker Sandbox Escape To macOS Host Files

vulnerability-disclosurepatch-managementzero-day-exploitinitial-access

Summary

A critical container escape vulnerability, CVE-2026-77179, was disclosed by Docker on 15 September 2026, affecting Docker Sandboxes versions up to and including 0.41.x on macOS. The flaw allows malicious code running inside a virtio-fs-backed virtual machine to traverse outside the shared project directory and read or modify arbitrary files on the host filesystem, operating with the full privileges of the host account running the VM.

The vulnerability is rooted in a symlink-following weakness in the virtio-fs host server component. An attacker who can execute code inside the guest environment can craft symlinks that the host server resolves without adequate boundary enforcement, yielding arbitrary file read and write on the macOS host. No public exploit has been confirmed at the time of disclosure, though the severity of the primitive makes weaponisation a realistic near-term prospect.

Docker has advised all users to upgrade the affected component immediately. Given that Docker Sandboxes is commonly used in developer workflows, the affected population spans individual developers through to enterprise engineering teams, where a compromised development environment could serve as a stepping-stone into broader internal systems.

Timeline

  1. 17 September 2026
    The Hacker News publishes technical coverage of the container escape
    Wider technical press coverage detailed the escape mechanism, noting that malicious guest code could read or modify arbitrary macOS host files with the privileges of the host account running the virtual machine.
  2. 15 September 2026
    Docker discloses CVE-2026-77179 and advises immediate upgrade
    Docker published a security advisory identifying a critical symlink-following flaw in the virtio-fs host server component of Docker Sandboxes versions up to 0.41.x, recommending users upgrade the affected component. VulDB simultaneously catalogued the entry, classifying it as very critical.

Want the full picture?

Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.