ZDI-26-643: Oracle VirtualBox VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-60162.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be able to execute high-privileged code on the target guest system. This is therefore relevant where a guest has already been significantly compromised or where high-privilege code execution is available to an untrusted local user.
What is the security impact of successful exploitation?
Successful exploitation allows disclosure of sensitive information from an affected Oracle VirtualBox installation. The issue is classified as an out-of-bounds read in the VMSVGA component and has a CVSS rating of 6.1.