Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
The whole pitch for Docker Sandboxes is that you can let an agent run wild inside a VM. CVE-2026-77179 (CVSS 9.4) undercuts that on macOS: guest code could swap a parent directory for a symlink and then read or write files anywhere on the host, well outside the shared project directory. A second bug let the guest make the host connect to arbitrary AF_UNIX sockets. Fixed in 0.42.0. No known exploitation yet - but “yet” is doing a lot of work.