Guest to host escape

VirtualBox emulates the guest's hardware in host-side processes. Every emulated device parses guest-controlled input, so a memory-corruption flaw runs code on the host as the user running the VM. VirtualBox's broad, open-source device set makes this a well-studied surface, with public exploit chains for several devices. The surface splits by device.

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more