Docker Desktop patch addresses critical security flaws enabling host compromise

1 min read
Source: The Hacker News
Docker Desktop patch addresses critical security flaws enabling host compromise
Photo: The Hacker News
TL;DR Summary

Docker has released version 4.44.3 to fix a critical vulnerability (CVE-2025-9074) in Docker Desktop for Windows and macOS that could allow attackers to escape containers and gain full host access, with a CVSS score of 9.3. The flaw stems from unauthenticated access to the Docker Engine API, enabling malicious containers to compromise the host system, especially on Windows, while Linux remains unaffected.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

89%

55062 words

Want the full story? Read the original article

Read on The Hacker News