Executive brief
A security vulnerability exists in Oracle VM VirtualBox, a software tool used to run multiple operating systems on a single computer. A highly privileged attacker with existing access to the host system could exploit this flaw to take full control of the VirtualBox environment. Because this exploit involves a 'scope change,' an attacker could potentially move beyond the virtual machine to impact the underlying host or other connected systems.
Technical details
This vulnerability is located in the Core component of Oracle VM VirtualBox version 7.2.12. It is classified as difficult to exploit (AC:H) and requires the attacker to have high-level privileges (PR:H) and local logon access to the infrastructure where VirtualBox is executing. The exploit results in a scope change (S:C), meaning a successful attack can extend beyond the VirtualBox security boundary to impact additional products or the host operating system. Successful exploitation can lead to a complete takeover of the VirtualBox instance, impacting confidentiality, integrity, and availability. Oracle addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle VM VirtualBox 7.2.12
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published.