Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Docker Flaw on macOS Exposes Host Files

Critical Docker Flaw on macOS Exposes Host Files

Posted on September 18, 2026 By CWS

A significant security flaw affecting Docker Sandboxes on macOS has been identified, allowing malicious code within a virtual machine to access host files. This vulnerability, detailed by Docker on September 15, poses a critical risk to systems running versions 0.28.0 up to but not including 0.42.0. The issue was addressed with the release of version 0.42.0 on September 7.

Understanding the Docker Vulnerability

The flaw, known as CVE-2026-77179, permits code running in a Docker Sandbox to escape its designated directory and access or modify files on the host system. This means any malicious code executed within the virtual machine gains the permissions of the host account. The vulnerability is considered critical, with a CVSS score of 9.4, and primarily affects macOS users.

While no instances of exploitation have been reported, both Docker and the Cybersecurity and Infrastructure Security Agency (CISA) have acknowledged the flaw. CISA’s records indicate no known exploitation, and the vulnerability is absent from its Known Exploited Vulnerabilities catalog as of September 16.

Technical Details and Implications

The flaw exploits the virtio-fs host server, which facilitates file sharing between the host and the virtual machine. By manipulating symlinks, a malicious guest could potentially execute code on the host. Docker’s documentation previously stated that symlinks outside the shared directory would not be followed, yet this vulnerability challenges that assurance.

In addition to CVE-2026-77179, another vulnerability, CVE-2026-79994, was identified. Rated as high severity with a CVSS score of 8.7, it impacts the Unix socket relay in versions 0.37.0 through 0.41.9. This flaw could allow unauthorized access to Unix sockets outside the workspace, compromising host-side capabilities.

Recommended Actions and Future Outlook

To mitigate these vulnerabilities, Docker advises users to upgrade to version 0.42.0 or later. The latest release, version 0.43.0, was made available on September 15. For those unable to update immediately, Docker suggests using clone mode to limit host file exposure. This mode ensures that the project directory is mounted read-only, offering some protection against unauthorized modifications.

Both vulnerabilities underscore the importance of regular software updates and adherence to security best practices. As Docker continues to improve its sandboxing technology, users are encouraged to stay informed about potential threats and apply updates promptly to safeguard their systems.

The Hacker News Tags:artificial intelligence, CVE-2026-77179, CVE-2026-79994, cyber threat, Cybersecurity, Docker, Docker Sandboxes, host file exposure, macOS, Security, software update, tech news, Unix socket, virtual machines, Vulnerability

Post navigation

Previous Post: OpenAI Reveals Security Breaches in AI Model Operations
Next Post: MIND’s $72M Boost for AI-Enhanced Data Protection

Related Posts

New Malware SharkLoader Deploys Cobalt Strike New Malware SharkLoader Deploys Cobalt Strike The Hacker News
APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine The Hacker News
WP Maps Pro Vulnerability Exploited to Create Admin Accounts WP Maps Pro Vulnerability Exploited to Create Admin Accounts The Hacker News
Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks The Hacker News
Vietnamese Hackers Use PXA Stealer, Hit 4,000 IPs and Steal 200,000 Passwords Globally Vietnamese Hackers Use PXA Stealer, Hit 4,000 IPs and Steal 200,000 Passwords Globally The Hacker News
AI-Powered Typosquatting Threatens Supply Chains AI-Powered Typosquatting Threatens Supply Chains The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • FBI Shuts Down Major DDoS-for-Hire Platform NightmareStresser
  • MIND’s $72M Boost for AI-Enhanced Data Protection
  • Critical Docker Flaw on macOS Exposes Host Files
  • OpenAI Reveals Security Breaches in AI Model Operations
  • RatHat Malware Exploits ADB for Persistent Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • FBI Shuts Down Major DDoS-for-Hire Platform NightmareStresser
  • MIND’s $72M Boost for AI-Enhanced Data Protection
  • Critical Docker Flaw on macOS Exposes Host Files
  • OpenAI Reveals Security Breaches in AI Model Operations
  • RatHat Malware Exploits ADB for Persistent Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark