Flatpak stack CVEs reopen the desktop sandbox trust question
A burst of bubblewrap, xdg-dbus-proxy, and Flatpak fixes shows how setup-time symlink tricks and D-Bus filter gaps still undermine the isolation users treat as a boundary.
By tarpitA burst of bubblewrap, xdg-dbus-proxy, and Flatpak fixes shows how setup-time symlink tricks and D-Bus filter gaps still undermine the isolation users treat as a boundary.
By tarpitCVE-2026-94422 let apps bypass D-Bus message filters and run code outside the sandbox.
By tarpitThe fix closes a setup-time traversal that could let a malicious app image plant files on the host via Flatpak and similar tools.
By nonceThe stable update closes symlink and path-traversal flaws that broke app isolation, with CVE IDs still pending.
By tarpit