CVE Tools
Back to feed
Patch released Docker Sandboxes ai-ml Docker web-app

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

Docker has fixed CVE-2026-77179, a macOS flaw in Docker Sandboxes 0.28.0 up to but not including 0.42.0 that could let malicious guest code use a symlink race to access or alter host files under the VM host account. The 0.42.0 release also resolves CVE-2026-79994, affecting versions 0.37.0 through 0.41.9, which could redirect authorized Unix socket connections to sockets outside the workspace. Docker reports no known exploitation; users should update to 0.42.0 or later, or use clone mode and avoid read-write host mounts until they can update.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store