Executive brief
A security vulnerability exists in Oracle VM VirtualBox, a software tool used to run multiple operating systems on a single computer. An attacker who already has high-level administrative access to the physical computer or server can exploit this flaw to view sensitive data they should not be able to see. While the risk is limited to data theft, the breach could potentially affect other software running on the same system.
Technical details
This vulnerability is located in the Core component of Oracle VM VirtualBox. It is classified as an information disclosure flaw that allows a high-privileged attacker with local logon access to the host infrastructure to compromise the virtualization environment. The exploit results in unauthorized read access to a subset of data accessible to VirtualBox. Notably, the CVSS vector indicates a scope change (S:C), suggesting that the impact of the vulnerability can extend beyond the VirtualBox security boundary to the host or other guest systems. The vulnerability is considered easily exploitable once the attacker has achieved the necessary high-privilege local access.
Affected products
- Oracle VM VirtualBox 7.2.12
Timeline
- 2026-07-21: advisory: Published by Oracle in the July 2026 Critical Patch Update