Skip to finding
important · Research — Containers

A Docker VMM guest can escape its shared workspace into arbitrary macOS host files.

Affects

Docker VMM, the macOS virtual-machine backend used by Docker Sandboxes and optionally by Docker Desktop.

By unlinking an open workspace file and replacing its parent with a symlink, guest code makes virtio-fs reopen the saved pathname outside the authorized workspace.

Detail and 3 sources

The result is host-user file read or overwrite, with code execution available through writable startup or configuration files; a three-line reproducer is public.

Docker Desktop 4.88.0 contains the fix.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 20, 2026