
I found a vulnerability in Oracle VirtualBox (CVE-2026-21957) back in September 2025. It can be turned into AAR/AAW, and then escaping the VM is pretty easy. I originally planned to find a vulnerability for Pwn2Own, but since I found the vuln in September, sitting on a practical vuln for that long didn’t feel very ethical, so I eventually reported it to ZDI. But I still finished the exploitation + demo video as practice.
Post summary
The author discovered CVE‑2026‑21957 in Oracle VirtualBox, demonstrated an exploitation PoC via a demo video, reported it to ZDI, and provided some technical detail about VM escape, but no patch or evidence of wild exploitation is mentioned.

