Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
- ID
- 25850
- Status
- summarized
- Published
- 17 Sep 2026, 11:37 PM
- Fetched
- 18 Sep 2026, 12:41 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 8.5
- Created
- 18 Sep 2026, 12:44 PM
- Tags
- Audience
- developersvibe_codersai_agent_users
What happened
Docker Sandboxes on macOS had a critical sandbox-escape flaw (CVE-2026-77179) affecting versions 0.28.0 through <0.42.0, fixed in 0.42.0 on September 7. Malicious code inside a sandbox VM—such as a compromised AI coding agent—could exploit a virtio-fs symlink-following bug to read or modify files anywhere on the host with the VMM user's privileges, defeating the sandbox's entire isolation purpose. A second high-severity flaw (CVE-2026-79994, CVSS 8.7) in the Unix domain socket relay was also fixed in the same release.
Why it matters
If you run AI coding agents inside Docker Sandboxes on macOS and haven't updated to 0.42.0, your host filesystem is exposed to whatever the agent installs or executes. The sandbox boundary you rely on to safely run untrusted agent-generated code is broken on versions below 0.42.0—update now and audit whether any agent sessions ran before the patch.
Discussion angle
This flaw exposes the core assumption that sandboxed AI agents can't touch your host—if you're letting coding agents run arbitrary commands and install packages, what's your actual isolation strategy beyond Docker Sandboxes, and would you have caught this symlink escape yourself?