important · Privilege escalation
A malicious Flatpak application can cross the desktop D-Bus sandbox and execute code as the user.
Affects
xdg-dbus-proxy, the D-Bus filtering proxy used by Flatpak and some other Linux application sandboxes.
xdg-dbus-proxy accepted a chosen reply serial on a non-reply message, treated it as an allowed reply and permitted the application to invoke a host-session D-Bus service. Release 0.1.9 fixes the filter.