Docker patched a sandbox escape vulnerability (CVE-2026-77179) in its hypervisor for Mac that allowed containers to read and write the host filesystem using a symlink-based attack. The flaw affected Docker Desktop with VMM enabled and Docker Sandboxes, and has been fixed in Docker Desktop 4.88.0 and Docker Sandboxes 0.42.0.