Docker Disaster: Critical Vulnerability Leaves Windows & macOS Exposed!
A critical vulnerability in Docker Desktop for Windows and macOS allows malicious containers to compromise the host even with Enhanced Container Isolation active. A server-side request forgery (SSRF) now identified as CVE-2025-9074, it scored a severity rating of 9.3. Docker swiftly addressed it in version 4.44.3.

Hot Take:
Docker Desktop, what a host! In a plot twist worthy of a cyber-thriller, a bug allows a malicious container to throw a house party on your Windows and macOS without you even knowing. And all this while the Enhanced Container Isolation (ECI) sits on the sidelines, probably sipping a latte. Who knew Docker was such a gracious host?
Key Points:
- Critical vulnerability identified as CVE-2025-9074 in Docker Desktop for Windows and macOS.
- Ineffective Enhanced Container Isolation (ECI) protection against this vulnerability.
- Felix Boulet discovered the SSRF vulnerability, allowing unauthorized access.
- More severe implications for Windows users compared to macOS.
- Docker promptly addressed the issue in version 4.44.3.
Already a member? Log in here