<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Xdg-Dbus-Proxy (&lt; 0.1.9) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/xdg-dbus-proxy--0.1.9/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 14:25:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/xdg-dbus-proxy--0.1.9/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Sandbox Escape via D-Bus Message Filtering Bypass in xdg-dbus-proxy</title><link>https://feed.craftedsignal.io/briefs/2026-10-xdg-dbus-proxy-bypass/</link><pubDate>Fri, 02 Oct 2026 14:25:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-xdg-dbus-proxy-bypass/</guid><description>A vulnerability in xdg-dbus-proxy versions prior to 0.1.9 allows a compromised Flatpak application to bypass security filters and escape the sandbox via malformed D-Bus reply serials.</description><content:encoded><![CDATA[<p>CVE-2026-94422 involves an incorrect implementation of message filtering within xdg-dbus-proxy versions prior to 0.1.9. This utility, which is responsible for enforcing security boundaries for Flatpak applications, fails to correctly validate the reply serial number field on D-Bus messages. An attacker who controls a sandboxed application can inject a reply serial number into non-reply messages, tricking the proxy into incorrectly routing or authorizing messages that should have been blocked. This vulnerability enables a malicious or compromised application to escape the intended sandbox isolation, leading to arbitrary code execution on the underlying host system. While primarily impacting Flatpak environments, the tool is also utilized by other sandboxing frameworks such as Firejail, expanding the potential attack surface. Defenders should prioritize updating xdg-dbus-proxy to version 0.1.9 or later across all Linux systems hosting sandboxed applications.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability results in a full bypass of the sandbox security model. A successful exploit allows a malicious application to execute arbitrary code with the privileges of the user running the sandbox, potentially leading to unauthorized data access, persistence, or lateral movement within the environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade xdg-dbus-proxy to version 0.1.9 or later on all Linux distributions.</li>
<li>Review environments utilizing sandboxing frameworks like Flatpak or Firejail to ensure the host package repository reflects the patched version.</li>
<li>Audit logs for unexpected D-Bus communications originating from sandboxed process IDs.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>sandbox-escape</category><category>privilege-escalation</category><category>linux</category></item></channel></rss>