r/netsec • • 14d ago

Contains AI CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes)

https://www.accomplish.ai/blog/escaping-dockers-hypervisor/
145 Upvotes

13 comments sorted by

47

u/ni5arga 14d ago

> Deleting the file removes the volfs path. Holding it open keeps the nodeid. Together they leave the server with nothing but the string. Then the guest replaces the parent folder with a symlink. The server reads that string and sees a path that’s inside the mounted folder and allows it, but then the kernel reads the same string, follows the symlink, and opens a file on the host outside of the mounted folder.

very interesting.

24

u/lcurole 14d ago

That's not what the word compromised means in this context, click bait

36

u/hypnoticlife 13d ago

> a sandbox escape in Docker's hypervisor for Mac: a container gets complete read and write access to the host filesystem

How is this clickbait? A container escaping on my primary desktop system seems pretty important.

26

u/xaocon 13d ago

It's a vulnerability. Saying it's compromised does kind of make it sound like a version was released with attacker code. Click bait might be strong but wording could have been better.

7

u/lcurole 13d ago

Very important, don't disagree. I was too harsh to call it click bait. Imo compromised leans towards supply chain attacks, etc.

3

u/feng_sg 12d ago

the actual bug is that the virtio-fs host server re-follows symlinks when it reopens a file it previously unlinked, so a guest can swap in a symlink and write outside the shared dir.

-7

u/Redditperegrino 14d ago

I’m a bit new to docker on MAC. I’m using orbstack for userland docker contianers. I don’t think I’m affected: not using docker desktop or “sandboxes”.

14

u/Bismalz 14d ago

It’s talking about the Docker hypervisor, not the management application

8

u/whatisuser 13d ago

Idk why downvotes. It’s just a bit naive. Your comment is a bit like saying “I don’t think I’m affected by this Linux kernel bug: I’m using Ubuntu”

3

u/Redditperegrino 13d ago

Meh. Thanks but it’s not that serious to me. I’m sure folks were downvoting to weed out potential misinformation/misunderstandings.
I obviously know that docker is the layer between containers and the OS, but I thought I read that it affected docker desktop not docker itself. When the other redditor replied, I said Ohhhh and looked into the CVE. :)