Executive brief
Oracle VM VirtualBox is hypervisor software used to run virtual machines on corporate infrastructure. A vulnerability in its core component allows a privileged user with local access to read sensitive data stored in VirtualBox-managed virtual machines, potentially exposing customer data or internal systems running on affected infrastructure.
Technical details
The vulnerability is a data access flaw in the Core component of Oracle VM VirtualBox that requires high-level privilege and local logon to the host system. An attacker with administrative access can exploit this to read critical data accessible to VirtualBox, with scope change indicating potential impact on guest virtual machines and connected systems. The attack vector is local with no user interaction required. Patch availability information is not detailed in the advisory.
Affected products
- Oracle VM VirtualBox 7.2.14
Timeline
- 2026-08-18: disclosed