Executive brief
Oracle VM VirtualBox, a popular virtualization tool used to run multiple operating systems on a single computer, contains a vulnerability in its core component. A highly privileged attacker with access to the host system can exploit this flaw to cause the software to hang or crash repeatedly. This results in a complete denial of service, potentially disrupting all virtual machines and services running on the affected infrastructure.
Technical details
A vulnerability exists in the Core component of Oracle VM VirtualBox version 7.2.12. The flaw is categorized as easily exploitable by a local attacker with high privileges (e.g., administrative access to the host OS). Successful exploitation results in a scope change (S:C), meaning the impact extends beyond the VirtualBox application itself to the wider host environment or other guest systems. The primary impact is on availability, where an attacker can trigger a persistent hang or a frequently repeatable crash, leading to a complete denial of service (DoS). The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle VM VirtualBox 7.2.12
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory