Executive brief
A security vulnerability exists in Oracle VM VirtualBox, a software tool used to run multiple operating systems on a single computer. A highly privileged attacker with existing access to the host system could exploit this flaw to gain unauthorized access to sensitive data or cause a partial service disruption. Because this issue involves a 'scope change,' an attacker might be able to move beyond the virtual machine to impact the underlying host or other connected systems.
Technical details
A vulnerability in the Core component of Oracle VM VirtualBox version 7.2.12 allows a high-privileged attacker with local logon access to the host infrastructure to compromise the application. The exploit is characterized as difficult (High Attack Complexity) but results in a Scope change (S:C), meaning the impact can extend beyond the VirtualBox environment to the host or other products. Successful exploitation can lead to unauthorized access to all VirtualBox data (High Confidentiality impact) and a partial denial of service (Low Availability impact). No user interaction is required for this attack.
Affected products
- Oracle VM VirtualBox 7.2.12
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60162
- 2026-07-21: advisory: Oracle Critical Patch Update (CPU) July 2026 released