Re: xdg-dbus-proxy: GHSA-r7hp-698j-2h6c: broadcast message filtering bypass
xdg-dbus-proxy broadcast filtering bypass is now tracked as CVE-2026-93676.
Simon McVittie reported on oss-security that CVE-2026-93676 was assigned for a broadcast message filtering bypass in xdg-dbus-proxy, also tracked as GHSA-r7hp-698j-2h6c. The note only confirms the identifier and does not describe exploitation or patch details.
- CVE-2026-93676 was assigned to xdg-dbus-proxy.
- The flaw is a broadcast message filtering bypass.
- It is also tracked as GHSA-r7hp-698j-2h6c.
- No exploitation is reported.
Vulnerabilities mentionedAll →
- CVE-2026-936763.2—D-Bus Broadcast Filtering Bypass in xdg-dbus-proxy Leaks Signals to Flatpak Appspublished · Flatpak project (freedesktop.org) xdg-dbus-proxy
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-93676 | D-Bus Broadcast Filtering Bypass in xdg-dbus-proxy Leaks Signals to Flatpak Apps xdg-dbus-proxy, the sandboxing helper that mediates D-Bus access for Flatpak applications, incorrectly filters D-Bus broadcast messages, bypassing the path, interface, and member restrictions configured for a sandbox. A malicious or compromised application running inside a Flatpak sandbox can listen for broadcast signals on the D-Bus session bus and the AT-SPI accessibility bus that should have been blocked, potentially exposing sensitive information to applications not authorized to receive it. Exploitation is local and low-impact: it requires the attacker to already control a sandboxed app on the target system and involves user interaction (e.g., the victim installing and running the malicious app), with only limited information disclosure and no integrity or availability impact (CVSS 3.2, low). All Linux systems that use xdg-dbus-proxy as part of Flatpak sandboxing are affected, with fixed versions defined in the upstream advisory GHSA-r7hp-698j-2h6c. No public proof of concept is known, the issue is not on the CISA KEV list, and there is no indication of exploitation in the wild. |
Posted by Simon McVittie on Sep 22 CVE-2026-93676 has been assigned. smcv
This source does not provide full text. Read it at seclists.org.