Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Summary

A critical vulnerability has been discovered in Docker Sandboxes on macOS, allowing malicious guest code to access and modify files outside of the shared project directory on the host machine. The escape operates with the privileges of the user running the virtual machine.

IFF Assessment

FOE

This vulnerability allows malicious actors to gain unauthorized access to host files, posing a significant risk to users.

Severity

9.0 Critical (AI Estimated)

The critical severity is based on the potential for unauthorized file access and modification of host system files, which is a high-impact outcome. The attack vector is likely to be straightforward given the context of a sandboxed environment.

Defender Context

This critical vulnerability highlights the importance of regularly updating Docker Desktop and monitoring shared directory permissions when using sandboxing features. Defenders should be aware of the potential for lateral movement from compromised containers into the host system, even within seemingly contained environments.

Read Full Story →