Public VirtualBox escapes recur in the network adapters (e1000, PCNet), the 3D graphics path, and the USB controllers, with several researchers publishing complete exploit chains. Because VirtualBox is open source, its device code is heavily audited, and working guest-to-host exploits for specific device bugs are well documented.
Recurring VirtualBox escape surfaces:
- e1000 / PCNet network adapters
- 3D acceleration (Chromium / VMSVGA)
- USB controllers (OHCI/EHCI/XHCI)
- The shared-folder and drag-and-drop handlers
Exploitation notes#
- The e1000 adapter is present by default on many guests, making it broadly reachable; 3D and specific USB controllers must be enabled.
- Escapes execute in the host VM process as the launching user, then escalate with a separate local privilege escalation.
- The surface map is in Guest to host escape.