logo

Sandbox Escape: Critical Flatpak Flaw Grants Full Host Access

ID: 60732803-c95d-5d52-ae17-21c507766a1c

STIX ID: report--60732803-c95d-5d52-ae17-21c507766a1c

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-09

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-34078, CVSS 9.3) in the Flatpak portal allows malicious Flatpak apps to use app-controlled symlinks to cause host paths to be mounted into the sandbox, enabling arbitrary host file read/write and code execution; the issue is patched in Flatpak 1.16.4 (and scheduled for 1.18.0), and temporary mitigation is to disable the flatpak-portal service, though this may cause app misbehavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.