Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Multiple Oracle VM VirtualBox Vulnerabilities Enables Complete Takeover Of VirtualBox

Oracle has disclosed several critical vulnerabilities in its Oracle VM VirtualBox software, which could potentially allow attackers to gain complete control over the VirtualBox environment.

Oracle has disclosed several critical vulnerabilities in its Oracle VM VirtualBox software, which could potentially allow attackers to gain complete control over the VirtualBox environment.

These vulnerabilities, described in the October 2025 Critical Patch Update (CPU), affect the Core component of VirtualBox versions 7.1.12 and 7.2.2. They enable high-privileged local attackers to compromise confidentiality, integrity, and availability, leading to significant consequences.

The vulnerabilities could result in full takeover scenarios, necessitating immediate patching for users relying on VirtualBox for development, testing, and secure isolation. Although there is no current evidence of active exploitation, the high CVSS scores indicate urgency.

Oracle's advisory notes that while exploitation requires high privileges and local access, the potential for unauthorized data access and denial-of-service attacks remains a severe threat.

Vulnerability Breakdown and Affected Versions

The October 2025 CPU addresses nine specific CVEs in VirtualBox's Core, all classified as local exploits without remote authentication .

These vulnerabilities stem from improper privilege handling and unsafe actions, allowing attackers with infrastructure logon to escalate control. The most severe, including CVE-2025-62587 through CVE-2025-62590 and CVE-2025-62641, have a CVSS 3.1 Base Score of 8.2, indicating high risk due to low attack complexity and changed scope.

CVE ID Product Component Remote Exploit without Auth.? CVSS VERSION 3.1 RISK Supported Versions Affected Notes Base Score Attack Vector Attack Complex User Interact

CVE-2025-62587 Oracle VM VirtualBox Core No 8.2 Local 7.1.12, 7.2.2

8.2 Local Low None

CVE-2025-62588 Oracle VM VirtualBox Core No 8.2 Local 7.1.12, 7.2.2

8.2 Local Low None

CVE-2025-62589 Oracle VM VirtualBox Core No 8.2 Local 7.1.12, 7.2.2

These vulnerabilities, described in the October 2025 Critical Patch Update (CPU), affect the Core component of VirtualBox versions 7.1.12 and 7.2.2.
Chloe Simmons · Thehackingpost

8.2 Local Low None

CVE-2025-62641 Oracle VM VirtualBox Core No 8.2 Local 7.1.12, 7.2.2

8.2 Local Low None

CVE-2025-62590 Oracle VM VirtualBox Core No 8.2 Local 7.1.12, 7.2.2

8.2 Local Low None

CVE-2025-61760 Oracle VM VirtualBox Core No 7.5 Local 7.1.12, 7.2.2

7.5 Local High Required

CVE-2025-61759 Oracle VM VirtualBox Core No 6.5 Local 7.1.12, 7.2.2

6.5 Local Low None

CVE-2025-62591 Oracle VM VirtualBox Core No 6.0 Local 7.1.12, 7.2.2

Advertisement

6.0 Local Low None

CVE-2025-62592 Oracle VM VirtualBox Core No 6.0 Local 7.1.12, 7.2.2

6.0 Local Low None

Lower-severity flaws like CVE-2025-61759 and CVE-2025-62591 to 62592 score 6.0 to 6.5, focusing on confidentiality breaches without integrity or availability disruption.

All vulnerabilities require local access but can propagate beyond VirtualBox due to scope changes. Successful exploitation could result in the complete takeover of the VirtualBox environment , exposing sensitive virtual machine data and enabling malware persistence across isolated systems.

For enterprises using VirtualBox in development pipelines or as a lightweight hypervisor, this poses risks of data leaks, ransomware deployment , or lateral movement in networks.

Individual developers might face personal data compromise if running untrusted guest OSes. The high integrity and availability impacts (scoring High) could cause crashes or unauthorized modifications, disrupting workflows.

While no public proofs-of-concept exist, the flaws’ similarity to past virtualization bugs raises concerns about targeted attacks.

Oracle urges users to apply the October 2025 CPU patches immediately, available via the official download portal.

Beyond patching, organizations should enforce least-privilege access, monitor high-privileged accounts, and audit VirtualBox configurations for unnecessary exposures.

Disabling unused features and isolating VirtualBox instances in segmented networks can mitigate risks. For those unable to patch promptly, temporary workarounds include restricting logon privileges and validating system integrity regularly.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories