HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Docker Desktop for macOS Inference Server Sandbox Escape (CVE‑2026‑XXXX) Enables Local Privilege Escalation

A high‑severity vulnerability in Docker Desktop for macOS lets a low‑privileged attacker break out of the model‑runner sandbox and execute code as the current user. The issue highlights the need for continuous control mapping and audit evidence to satisfy SOC 2 isolation requirements.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

Docker Desktop for macOS Inference Server Sandbox Escape (CVE‑2026‑XXXX) Enables Local Privilege Escalation

What Happened — A newly disclosed vulnerability (CVE‑2026‑XXXX, CVSS 8.8) in Docker Desktop for macOS allows a low‑privileged attacker who can run code inside the model‑runner sandbox to break out of the sandbox, gain the privileges of the current macOS user, and execute arbitrary code on the host. Docker has published a patch that tightens the sandbox’s allow‑list.

Why It Matters for Compliance & Audit Readiness

  • The flaw directly violates SOC 2 CC6.1 (system operations) and CC7.1 (change management) requirements for “enforced isolation of execution environments.”
  • Continuous‑compliance programs must demonstrate that sandbox controls are mapped, monitored, and evidentially verified after each software update.
  • Verisq’s Control Mapping capability can automatically capture the remediation patch, map it to the relevant SOC 2 controls, and provide audit‑ready evidence of remediation.

Who Is Affected — Organizations that develop, test, or run containerized AI/ML workloads on macOS workstations—primarily technology SaaS firms, cloud‑infrastructure teams, and R&D groups across most verticals.

Recommended Actions

  • Apply Docker’s July 2026 security update immediately.
  • Update your internal control inventory to reflect the hardened sandbox profile and map the change to SOC 2 CC6.1/CC7.1.
  • Enable continuous evidence collection for sandbox configuration drift to prove ongoing compliance. Source: Zero Day Initiative advisory

Technical Notes

  • CVE ID: CVE‑2026‑XXXX
  • CVSS: 8.8 (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
  • Attack vector: Local privilege escalation via permissive allow‑list in the inference server sandbox.
  • Patch reference: https://github.com/docker/model-runner/commit/980388697b46b799ebc831f26fa83e4e6130f80a
📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-451/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →