Docker Desktop for macOS Inference Server Sandbox Escape (CVE‑2026‑XXXX) Enables Local Privilege Escalation
What Happened — A newly disclosed vulnerability (CVE‑2026‑XXXX, CVSS 8.8) in Docker Desktop for macOS allows a low‑privileged attacker who can run code inside the model‑runner sandbox to break out of the sandbox, gain the privileges of the current macOS user, and execute arbitrary code on the host. Docker has published a patch that tightens the sandbox’s allow‑list.
Why It Matters for Compliance & Audit Readiness
- The flaw directly violates SOC 2 CC6.1 (system operations) and CC7.1 (change management) requirements for “enforced isolation of execution environments.”
- Continuous‑compliance programs must demonstrate that sandbox controls are mapped, monitored, and evidentially verified after each software update.
- Verisq’s Control Mapping capability can automatically capture the remediation patch, map it to the relevant SOC 2 controls, and provide audit‑ready evidence of remediation.
Who Is Affected — Organizations that develop, test, or run containerized AI/ML workloads on macOS workstations—primarily technology SaaS firms, cloud‑infrastructure teams, and R&D groups across most verticals.
Recommended Actions
- Apply Docker’s July 2026 security update immediately.
- Update your internal control inventory to reflect the hardened sandbox profile and map the change to SOC 2 CC6.1/CC7.1.
- Enable continuous evidence collection for sandbox configuration drift to prove ongoing compliance. Source: Zero Day Initiative advisory
Technical Notes
- CVE ID: CVE‑2026‑XXXX
- CVSS: 8.8 (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- Attack vector: Local privilege escalation via permissive allow‑list in the inference server sandbox.
- Patch reference: https://github.com/docker/model-runner/commit/980388697b46b799ebc831f26fa83e4e6130f80a