A malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host. This issue exists in Flatpak before 1.18.1 and is a different vulnerability than CVE-2026-76925. The vulnerability arises from Flatpak's creation of app data directories in every sandbox on every app launch, where components of the path can be attacker- [truncated]
CVE-2026-34079 is a high-severity vulnerability in Flatpak, a Linux application sandboxing and distribution framework. Prior to version 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. The vulnerability is fixed in version 1.16.4. [truncated]
CVE-2026-34078 is a critical vulnerability in the Flatpak Linux application sandboxing and distribution framework. Prior to version 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. The vulnerability is fi [truncated]
CVE-2026-34080 is a medium-severity vulnerability in xdg-dbus-proxy, a filtering proxy for D-Bus connections. The vulnerability allows clients to intercept D-Bus messages they should not have access to due to a policy parser issue. The issue arises from the proxy's failure to properly handle eavesdrop restrictions, specifically when there is a space before the equals sign in policy rules. This vulnerabili [truncated]