HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Docker Sandbox Escape (CVE‑2026‑77179) Lets Guest Code Access Any macOS Host File

Docker disclosed a critical sandbox‑escape flaw (CVE‑2026‑77179) that allows malicious code inside a Docker Sandbox VM on macOS to read or modify files outside the shared project directory. The issue impacts all pre‑patch Docker Desktop for macOS installations and highlights the need for verifiable isolation controls in audit‑ready environments.

Verisq™ Intelligence · 📅 September 18, 2026 · 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
5 recommended
📰
Source
thehackernews.com

Critical Docker Sandbox Escape (CVE‑2026‑77179) Allows Guest Code to Read/Modify macOS Host Files

What It Is — Docker disclosed a critical sandbox‑escape vulnerability (CVE‑2026‑77179) that lets malicious code running inside a Docker Sandbox VM on macOS break out of the shared project directory and access any file on the host system. The escape runs with the privileges of the user account that launched the VM.

Exploitability — The flaw is publicly disclosed, rated Critical (CVSS ≥ 9.0), and a proof‑of‑concept has been demonstrated by Docker’s own security team. No public exploit‑as‑a‑service is known yet, but the attack surface is wide because Docker is used in development, CI/CD pipelines, and production workloads on macOS.

Affected Products — Docker Desktop for macOS (all versions prior to the September 2026 security patch).

Why It Matters for Trust & Control Assurance

  • Demonstrates a gap in the isolation and containment control objective that underpins many frameworks (e.g., NIST CSF 2.0 – “Protect” function).
  • Without proper evidence that container runtimes enforce host‑file segregation, auditors may question the organization’s ability to maintain a defensible audit trail for data‑handling controls.
  • Continuous control mapping and evidence collection (Verisq Trust Center) can surface this gap early, allowing enterprises to prove they have mitigated the risk before a breach occurs.

Recommended Actions

  1. Apply Docker’s September 2026 security update immediately.
  2. Review and harden container runtime configurations: disable unnecessary host‑directory mounts, enforce least‑privilege user namespaces, and enable macOS System Integrity Protection (SIP) for Docker processes.
  3. Integrate the updated Docker version into your control‑mapping repository and capture remediation evidence for audit readiness.
  4. Deploy host‑file integrity monitoring to detect unauthorized modifications.

Source: The Hacker News – Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

📰 Original Source
https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →