Shabbat Shalom.
@Docker has issued a critical level (!!) CVE-2026-77179, reported by
@Accomplish_ai researcher
@orenyomtov.
If you use Docker Sandboxes, run sbx --version. Make sure you’re running 0.42.0 or later.
If you use Docker Desktop, you want 4.88.0 or later
Docker Desktop and Docker Sandboxes are both affected. Docker Desktop is only affected if Docker VMM is turned on in Settings.
It’s a good thing we found it now, because Docker VMM is scheduled to become the default for Docker Desktop at the end of October 2026!
The escape is in Docker's hypervisor for Mac: a container gets complete read and write access to the host filesystem.
Read the full details of this escape in our blog: