Executive brief
A vulnerability exists in Oracle VM VirtualBox, a popular virtualization tool used to run multiple operating systems on a single computer. A high-privileged attacker with access to the host system can exploit the VMSVGA graphics component to gain unauthorized access to sensitive data. This could lead to a breach of confidentiality across the entire virtualized environment, potentially impacting other systems beyond the virtual machine itself.
Technical details
This vulnerability is classified as Improper Privilege Management (CWE-269) within the VMSVGA device component of Oracle VM VirtualBox. It is exploitable by a high-privileged attacker with local logon access to the infrastructure where VirtualBox is executing. The flaw is notable for a 'scope change' (S:C), meaning an exploit can impact components beyond the immediate security scope of the VirtualBox application. Successful exploitation results in unauthorized access to critical data or complete access to all data accessible by the VirtualBox process. The vulnerability is present in version 7.2.8.
Affected products
- Oracle VM VirtualBox 7.2.8
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published