Docker disclosed a critical sandbox escape vulnerability in Docker Sandboxes for macOS that permits malicious guest code to read and modify arbitrary files on the host system. The flaw, tracked as CVE-2026-77179, allows an attacker with code execution inside a Docker container to break out of the project directory that was intentionally shared and access files anywhere on the compromised macOS machine.
The vulnerability carries a CVSS Critical severity rating. An attacker exploiting this flaw operates with the full privileges of the host user account running the Docker Sandboxes virtual machine, meaning potential damage extends to any files that account can touch. This eliminates the isolation layer Docker Sandboxes were designed to provide.
Docker Sandboxes represents the company's answer to resource-hungry virtualization on Apple Silicon Macs. Rather than running full virtual machines via hypervisor frameworks, Docker Sandboxes uses a lightweight containerization approach to isolate workloads. The project directory mechanism allows developers to mount specific folders into containers for development workflows. This vulnerability fundamentally breaks that trust boundary.
The attack chain requires an attacker to first execute malicious code within a container running on Docker Sandboxes. This could happen through a compromised image, a vulnerable application inside the container, or a supply chain attack via a dependency. Once code execution is achieved, the attacker can exploit CVE-2026-77179 to traverse outside the mounted project directory and reach sensitive files on the host.
Potential targets include SSH private keys stored in the .ssh directory, API credentials in configuration files, browser cookies and cached login tokens, database files, and source code repositories outside the shared project folder. An attacker could also modify system files or application configurations to maintain persistence or escalate privileges further.
The timing of this disclosure on September 15 suggests Docker has already issued patches. Organizations running Docker Sandboxes on macOS should immediately update to the patched version. Users should assume any untrusted container images run locally represent a direct risk to host file security until patches are applied.
This vulnerability highlights a broader pattern in container security. Sandbox escapes in container runtimes expose the assumption that containers provide meaningful isolation. While containers excel at process-level separation, kernel vulnerabilities and architectural design flaws can undermine that isolation. For macOS users in particular, the lighter virtualization model Docker chose comes with tradeoffs compared to heavier hypervisor-based approaches.
Security teams should review their container image sources and ensure only trusted images are used in Docker Sandboxes environments. Implementing network segmentation to limit damage from host compromise also reduces blast radius. For teams handling sensitive data or credentials, consider whether containers should have filesystem access to host directories at all, or whether a more restricted data-passing mechanism suits the workflow.
Docker Sandboxes adoption has grown among macOS developers seeking faster container iteration than traditional virtual machines. This vulnerability impacts that development ecosystem directly. Patch deployment velocity will be critical to limiting real-world exploitation.
