Flatpak released 1.16.4 to fix four security issues affecting earlier versions, led by CVE-2026-34078, a critical flaw in the flatpak-portal D-Bus service that can let a malicious sandboxed app escape confinement, access arbitrary host files, and potentially execute code in the host context. The bug stems from acceptance of app-controlled symlinked sandbox-expose paths that are resolved and mounted from the host into the sandbox. Flatpak also patched CVE-2026-34079, which allows arbitrary file deletion on the host through improper validation during ld.so cache cleanup, along with a low-severity arbitrary file-read issue in the flatpak-system-helper context when a system OCI repository is configured and a cross-user CancelPull flaw.
The fixes were issued in Flatpak 1.16.4 and the development branch 1.17.4, with later 1.16.5 and 1.17.5 releases addressing regressions introduced by the critical patch; the fixes are also slated for 1.18.0. Multiple Linux distributions, including Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch, and Fedora, were reported as affected or tracking updates, and Debian published a security advisory for Flatpak. Flatpak and downstream advisories urged administrators to upgrade promptly, while temporary mitigation for the sandbox-escape issue included disabling or masking the Flatpak Portal, with the warning that some applications may stop working correctly.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Debian published security advisory DSA 6207-1 for Flatpak, indicating a distribution-level security update in response to the disclosed vulnerabilities. The reference provides the advisory identifier and publication date.
In an oss-sec reply, Simon McVittie said Flatpak maintainers were unsure whether the arbitrary read issue in the flatpak-system-helper context constituted a real vulnerability and handled it conservatively without assigning a CVE. He added that he could not identify a realistic scenario where files readable by the unprivileged helper account would not already be readable by the user running Flatpak.
An oss-sec post disclosed four Flatpak security issues affecting versions prior to 1.16.4 and said fixes were introduced in 1.16.4 and 1.17.4. The post also noted that follow-up releases 1.16.5 and 1.17.5 addressed regressions caused by the critical CVE-2026-34078 fix.
Flatpak released version 1.16.4 to address four vulnerabilities, including critical CVE-2026-34078, CVE-2026-34079, an arbitrary read issue in flatpak-system-helper, and a cross-user CancelPull flaw. Administrators were advised to upgrade to the patched release.
CVE-2026-34078 and CVE-2026-34079 were published, documenting a critical sandbox escape and an arbitrary file deletion vulnerability affecting Flatpak versions prior to 1.16.4. The records note that both issues were fixed in Flatpak 1.16.4.
GitHub security advisories were published for CVE-2026-34078, a complete sandbox escape, and CVE-2026-34079, an arbitrary host file deletion flaw in Flatpak. Both advisories state the issues were patched in Flatpak 1.16.4 and are expected to be included in the upcoming 1.18.0 release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
lists.debian.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcehelpnetsecurity.com
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcecvefeed.io
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.