Executive brief
Oracle VM VirtualBox is virtualization software that allows users to run multiple operating systems on a single computer. A vulnerability in the Core component allows a local attacker with system access to crash the virtualization platform or corrupt data, disrupting virtual machine operations and potentially causing data loss.
Technical details
This is an easily exploitable local vulnerability in the Core component of Oracle VM VirtualBox 7.2.14 that requires user interaction to trigger. The vulnerability allows an unauthenticated attacker with local system access to cause denial of service (system hang or crash) and unauthorized modification or deletion of VirtualBox data. The attack vector is local (AV:L), no elevated privileges are required (PR:N), and user interaction is necessary (UI:R). Successful exploitation results in high availability impact and some integrity impact, with no confidentiality impact. Patches are expected from Oracle.
Affected products
- Oracle VM VirtualBox 7.2.14
Timeline
- 2026-08-18: disclosed