HomeSecurityDocker vulnerability allows MacOS users to download container images

Docker vulnerability allows MacOS users to download container images

A new vulnerability in Docker Desktop 's Registry Access Management (RAM) feature leaves macOS users vulnerable to unauthorized container image downloads, undermining critical container security mechanisms.

See also: New Docker 1-Click RCE attack exploits API misconfigurations

Docker vulnerability

The vulnerability, reported as CVE-2025-4095 , allows developers to bypass administrator-imposed access restrictions to image registries , potentially exposing organizations to malicious container images or unapproved software dependencies. RAM is designed to restrict container image downloads to only pre-defined registries, such as Docker Hub , Amazon ECR , or private repositories. Through DNS-level blocking, RAM prevents access to untrusted sources, making it a key component of software supply chain security.

However, when organizations enforce login policies on macOS through configuration profiles (a common corporate deployment method), RAM policies are not properly enabled.

The vulnerability is due to a misconfiguration of the Docker Desktop policy enforcement engine. On macOS, Docker runs inside a Hyperkit virtual machine , with RAM policies being applied at the daemon level after user authentication.

See also: Hackers exploit Docker Servers API for Crypto Mining attacks

Configuration profiles—XML or mobileconfig used to automate settings—incorrectly prioritize login enforcement over enabling RAM policies.

Docker vulnerability allows MacOS users to download container images

This causes a race condition, in which the Docker daemon starts before the RAM policies are loaded, leaving the registers unchecked until the next system reboot.

Affected versions include Docker Desktop 4.36.0 through 4.40.x for macOS. The CVSS score for v4.0 is 4.3 (Moderate), however this underestimates the operational risk as attackers can exploit this vulnerability to inject malicious images into software development pipelines.

See also: Docker fixes critical vulnerability in Docker Engine

Related to the above is the importance of “secure-by-design” in deployment platforms like Docker. When security mechanisms like Registry Access Management (RAM) are not properly enabled or can be bypassed due to conditions like race conditions, trust is undermined throughout the software supply chain. This is especially critical in CI/CD (Continuous Integration/Continuous Deployment) environments, where even a single import of an unapproved or malicious container image can quickly propagate to production systems, with serious security and compliance implications.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS