Executive brief
A vulnerability in Oracle VM VirtualBox allows a user with low-level access to the host computer to take full control of the virtualization software. This could lead to unauthorized access to sensitive data, system instability, or the complete takeover of the VirtualBox environment. The issue affects version 7.2.12 and requires the attacker to already have login access to the physical or virtual machine where the software is running.
Technical details
A vulnerability exists in the Core component of Oracle VM VirtualBox version 7.2.12. The flaw is categorized as easily exploitable and requires a low-privileged attacker to have local logon access to the infrastructure where VirtualBox is executing. Successful exploitation allows for a complete takeover of the Oracle VM VirtualBox instance, impacting confidentiality, integrity, and availability. The attack vector is local (AV:L) with low complexity (AC:L) and requires no user interaction (UI:N). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.
Affected products
- Oracle VM VirtualBox 7.2.12
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60150
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released