ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 6 sources: “Zero Day Initiative publishes six Oracle VirtualBox advisories (ZDI-26-639 through ZDI-26-644) covering VMSVGA, VirtioSCSI, and IDisplay local guest flaws” — merged summary and timeline →

ZDI-26-643: Oracle VirtualBox VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability

lowAdvisoryimportance 18CVE-2026-60162
AI summary · glm-5.3-flash

ZDI publishes ZDI-26-643 for CVE-2026-60162, an out-of-bounds read information disclosure flaw in Oracle VirtualBox VMSVGA, rated CVSS 6.1.

Zero Day Initiative published advisory ZDI-26-643 describing an out-of-bounds read in Oracle VirtualBox's VMSVGA component. Local attackers with the ability to execute high-privileged code on the guest system can disclose sensitive information. ZDI rated the issue CVSS 6.1 and assigned CVE-2026-60162.

  • Out-of-bounds read in VMSVGA leaks sensitive information
  • Requires high-privileged code execution on the guest
  • CVSS 6.1; tracked as CVE-2026-60162
VendorsOracle
ProductsVirtualBox
OrganizationsZero Day Initiative

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-60162
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component:

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L).

NVD description · AI analysis pending
6.1<1%
  • oracle vm virtualbox
Full article

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-60162.

This source does not provide full text. Read it at zerodayinitiative.com.