Executive brief
Oracle VM VirtualBox is a virtualization platform that allows organizations to run multiple operating systems on a single physical computer. A flaw in the Core component allows a privileged user with local access to read sensitive data stored by VirtualBox or data accessible to virtual machines running on the host. This could expose customer data, credentials, or confidential information across multiple virtual environments.
Technical details
This is a local privilege escalation vulnerability in Oracle VM VirtualBox's Core component affecting version 7.2.14 and likely other 7.x releases. The vulnerability requires high-level privileges and local logon access to the infrastructure where VirtualBox runs. The attack vector is local (AV:L) with low complexity (AC:L), and successful exploitation results in high confidentiality impact with scope change—meaning an attacker can read critical data not only within VirtualBox but potentially on the host system and connected virtual machines. No public exploit code is currently known, and a patch status from Oracle is not yet confirmed.
Affected products
- Oracle VM VirtualBox 7.2.14 (likely others in 7.x branch)
Timeline
- 2026-08-18: disclosed