Executive brief
Oracle VM VirtualBox is a widely-used virtualization platform that enables organizations to run multiple operating systems on a single computer. This vulnerability allows a local attacker with system access to cause the application to crash or become unresponsive, or to tamper with virtual machine data. While an attacker must interact with a user to exploit this issue, successful attacks can disrupt virtual machine operations and compromise the integrity of hosted systems.
Technical details
The vulnerability exists in the Core component of Oracle VM VirtualBox and is classified as an easily exploitable local issue requiring user interaction. The attack vector is local (AV:L) with no privilege requirements (PR:N), but requires user interaction (UI:R). A successful exploit can result in denial of service (application hang or crash) and unauthorized modification of accessible data within VirtualBox. The vulnerability affects version 7.2.16 and potentially other version 7.x releases. No details on the specific vulnerable code path or root cause are publicly available at this time.
Affected products
- Oracle VM VirtualBox 7.2.16 and other version 7.x releases
Timeline
- 2026-09-15: disclosed