Docker has fixed a critical sandbox escape vulnerability in Docker Sandboxes for macOS that allowed malicious guest code to access host files.

Reader brief
Through the Reader lens: A critical vulnerability, CVE-2026-77179, has been discovered in Docker Sandboxes for macOS that allows malicious code inside a virtual machine to escape the shared directory and read or modify host files. This flaw affects versions 0.28.0 through 0.41.9 and runs with the rights of the host user running the virtual machine. A second high-severity flaw, CVE-2026-79994, affecting Unix socket connections, was also addressed. Docker has released version 0.42.0 to resolve both issues, and no exploitation has been reported in the wild.
What to watch next
- Check for further updates regarding Docker Sandboxes as version 0.43.0 has already been released.
Sources1
All filed from IndiaNamed United States · accomplish.ai · Cyera Research Labs · Docker · Jurre van Bergen · Oren Yomtov · ThreatNotify
- [1]The Hacker NewsneutralCritical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files