CVE-2026-77179: On macOS, the virtio-fs host server used by Docker

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

Related briefings

Browse the CVE database

Read the full analysis on IntelFusions