Sandbox Escape: Critical Flatpak Flaw Grants Full Host Access
ID: 60732803-c95d-5d52-ae17-21c507766a1c
STIX ID: report--60732803-c95d-5d52-ae17-21c507766a1c
Feed Name: securityonline.info
Threat Score
A critical vulnerability (CVE-2026-34078, CVSS 9.3) in the Flatpak portal allows malicious Flatpak apps to use app-controlled symlinks to cause host paths to be mounted into the sandbox, enabling arbitrary host file read/write and code execution; the issue is patched in Flatpak 1.16.4 (and scheduled for 1.18.0), and temporary mitigation is to disable the flatpak-portal service, though this may cause app misbehavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
