Skip to finding
important · Privilege escalation

A malicious Flatpak application can cross the desktop D-Bus sandbox and execute code as the user.

Affects

xdg-dbus-proxy, the D-Bus filtering proxy used by Flatpak and some other Linux application sandboxes.

xdg-dbus-proxy accepted a chosen reply serial on a non-reply message, treated it as an allowed reply and permitted the application to invoke a host-session D-Bus service. Release 0.1.9 fixes the filter.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 24, 2026