A critical container escape vulnerability, CVE-2026-77179, was disclosed by Docker on 15 September 2026, affecting Docker Sandboxes versions up to and including 0.41.x on macOS. The flaw allows malicious code running inside a virtio-fs-backed virtual machine to traverse outside the shared project directory and read or modify arbitrary files on the host filesystem, operating with the full privileges of the host account running the VM.
The vulnerability is rooted in a symlink-following weakness in the virtio-fs host server component. An attacker who can execute code inside the guest environment can craft symlinks that the host server resolves without adequate boundary enforcement, yielding arbitrary file read and write on the macOS host. No public exploit has been confirmed at the time of disclosure, though the severity of the primitive makes weaponisation a realistic near-term prospect.
Docker has advised all users to upgrade the affected component immediately. Given that Docker Sandboxes is commonly used in developer workflows, the affected population spans individual developers through to enterprise engineering teams, where a compromised development environment could serve as a stepping-stone into broader internal systems.
Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.
We use analytics cookies to understand how visitors use Deltabridge and improve the site. They’re off until you accept. See our Privacy Policy.