important · Research — Containers
A Docker VMM guest can escape its shared workspace into arbitrary macOS host files.
Affects
Docker VMM, the macOS virtual-machine backend used by Docker Sandboxes and optionally by Docker Desktop.
By unlinking an open workspace file and replacing its parent with a symlink, guest code makes virtio-fs reopen the saved pathname outside the authorized workspace.
Detail and 3 sources
The result is host-user file read or overwrite, with code execution available through writable startup or configuration files; a three-line reproducer is public.
Docker Desktop 4.88.0 contains the fix.