Skip to content
Critical Vulnerabilities in Docker Sandboxes Expose macOS Hosts

Critical Vulnerabilities in Docker Sandboxes Expose macOS Hosts

First seen 17 Sep 2026, 16:30 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 18:24 UTC
  • CVE-2026-77179 allows Docker Sandboxes to escape and access host files on macOS.
  • CVE-2026-79994 exposes host data via Unix domain socket relay vulnerabilities.
  • Both vulnerabilities were patched in Docker version 0.42.0 released on September 7, 2026.

Docker has announced the resolution of two critical vulnerabilities in Docker Sandboxes affecting macOS systems. CVE-2026-77179 allows malicious code in a Docker virtual machine to escape its project directory and access host files, potentially leading to code execution. This flaw affects versions 0.28.0 to 0.41.9 and was patched in version 0.42.0 released on September 7, 2026. The second vulnerability, CVE-2026-79994, rated as High, involves a flaw in the Unix domain socket relay that could expose host data. Docker has not reported any known exploitation of these vulnerabilities, and the vulnerabilities were detailed in a security announcement on September 15, 2026. Users are advised to update to version 0.42.0 or later to mitigate these risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2021-12-10
CVE-2021-44228 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-12-14
CVE-2021-45046 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-12-18
CVE-2021-45105 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-01-31
CVE-2024-23653 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-01-31
CVE-2024-23650 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-01-31
CVE-2024-23652 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-01-31
CVE-2024-23651 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-01-31
CVE-2024-21626 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-02-01
CVE-2024-24557 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-06-20
Public exploit for CVE-2025-9074 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub

More articles in this cluster (5)

Following this threat?

Track CVE-2021-44228 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed