Executive brief
Oracle VM VirtualBox is a virtualization platform used to run multiple operating systems on a single computer. A vulnerability in its core component allows a high-privileged attacker with local access to read sensitive data and temporarily disrupt the virtualization service. This could expose confidential information from virtual machines or the host system and impact the availability of virtual environments.
Technical details
The vulnerability exists in the Core component of Oracle VM VirtualBox version 7.2.16 and affects the virtualization engine itself. It is easily exploitable by a high-privileged attacker (requiring administrative or host-level access) with local logon to the infrastructure. The attack has local attack vector (AV:L) and does not require user interaction. Successful exploitation results in unauthorized read access to a subset of VirtualBox data and the ability to cause partial denial of service. The vulnerability exhibits scope change (S:C), meaning attacks against VirtualBox can impact additional products beyond itself.
Affected products
- Oracle VM VirtualBox 7.2.16
Timeline
- 2026-09-15: disclosed