Executive brief
A security vulnerability exists in Oracle VM VirtualBox, a popular virtualization tool used to run multiple operating systems on a single computer. A highly privileged attacker with existing access to the host system could exploit this flaw to gain unauthorized read access to sensitive data. While the risk is localized to the host machine, the breach could potentially impact other software components running on that infrastructure.
Technical details
An information disclosure vulnerability (CWE-200) exists in the VMSVGA device component of Oracle VM VirtualBox version 7.2.8. The flaw is categorized as easily exploitable but requires the attacker to have high-level privileges and local logon access to the infrastructure where VirtualBox is executing. Successful exploitation results in a 'scope change' (S:C), meaning the attacker can read a subset of data accessible to VirtualBox that may belong to the host or other virtualized environments. The impact is limited to confidentiality, with no reported impact on system integrity or availability.
Affected products
- Oracle VM VirtualBox 7.2.8
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD record published