Docker sandbox flaw lets guest code escape and change macOS host files
Docker patched two flaws in Docker Sandboxes, the isolated micro-VM environments used to run untrusted code and AI-agent tasks, that let malicious guest code break out and read or modify files on the macOS host. The more serious, CVE-2026-77179 and scored 9.4, is in the file-sharing component: the host improperly follows symbolic links when reopening a file, so a guest can swap a directory for a symlink after a path is approved, escape the shared workspace, and touch arbitrary host files as the account running the VM, potentially leading to host code execution. A second flaw abuses the guest-to-host socket relay the same way. Both are fixed in version 0.42.0.
- Check
- Update Docker Sandboxes to version 0.42.0 or later on macOS developer machines, and minimize which host directories are mounted into sandboxes, keeping credentials and sensitive repositories out of shared paths.
- Affected
- Developers running Docker Sandboxes below 0.42.0 on macOS to isolate untrusted code or AI-agent tasks (CVE-2026-77179, CVE-2026-79994); malicious guest code can escape via symlink races and read or modify host files.
- Fix
- Patch to 0.42.0, treat sandboxes running untrusted code or AI agents as hostile, minimize host-mounted directories, keep secrets out of shared paths, and watch for unexpected host file changes from sandbox processes.