Patch released Docker Sandboxes ai-ml Docker web-app
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
CVE Tools coverage
Docker has fixed CVE-2026-77179, a macOS flaw in Docker Sandboxes 0.28.0 up to but not including 0.42.0 that could let malicious guest code use a symlink race to access or alter host files under the VM host account. The 0.42.0 release also resolves CVE-2026-79994, affecting versions 0.37.0 through 0.41.9, which could redirect authorized Unix socket connections to sockets outside the workspace. Docker reports no known exploitation; users should update to 0.42.0 or later, or use clone mode and avoid read-write host mounts until they can update.