Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files Swati KhandelwalSep 17, 2026Vulnerability / Artificial Intelligence Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions 0.28.0 up to but not including 0.42.0 on macOS, and was fixed in 0.42.0 on September 7. Docker Sandboxes runs each AI coding agent in its own small virtual machine with the project directory shared in. The code…
CVEs: CVE-2026-77179, CVE-2026-79994
Original source: thehackernews.com