Flatpak released 1.18.4, with the same fixes in development version 1.19.2, to address high-impact flaws affecting its Linux application sandboxing and distribution framework. The updates prevent malicious applications from abusing privileged operations to overwrite or delete arbitrary host files, including attacks involving empty files or a symlink to /run/host/monitor/resolv.conf. They also stop authenticated OCI repository download tokens from being exposed to other local users, restrict unsafe fields in .desktop and D-Bus .service files, and prevent sandboxed applications from signaling process groups containing host parent processes, an action that could terminate the desktop environment.
Earlier Flatpak 1.18.1 fixes addressed a broader set of symlink and path-traversal weaknesses, including sandbox escape conditions that enabled host filesystem read/write access, root-level arbitrary writes, arbitrary host-file reads, an anti-downgrade bypass, and a 32-bit buffer overflow. CVE assignments were published for the resolved issues, while two remained pending MITRE assignment at the time of the disclosure; a separate identifier, CVE-2026-76925, applies to a RHEL-specific backport issue rather than upstream Flatpak. Organizations should update deployed Flatpak installations to a fixed maintenance or development release and review systems where untrusted Flatpak applications may have run.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Flatpak released stable version 1.18.4 and development version 1.19.2 with fixes for privileged arbitrary-file overwrites and deletion, OCI authentication-token exposure, unsafe .desktop and D-Bus service-file fields, and sandboxed-app signals that could kill the desktop environment.
Simon McVittie published CVE assignments for the Flatpak vulnerabilities, while noting that the revokefs local-root-escalation issue and the .ld.so symlink issue still had pending MITRE requests. The notice also clarified that CVE-2026-76925 applied to a Red Hat backport and not upstream Flatpak.
Flatpak 1.18.1 addressed multiple vulnerabilities, including sandbox escape, local root privilege escalation, arbitrary host-file reads or writes, an anti-downgrade bypass, and a 32-bit buffer overflow. The fixes included flaws assigned CVE-2026-90616, CVE-2026-96275, CVE-2026-96276, CVE-2026-96279, CVE-2026-92162, CVE-2026-96280, CVE-2026-96281 and CVE-2026-96282, plus two issues awaiting MITRE assignments.
Flatpak 1.16.4 fixed CVE-2026-96284, an arbitrary-read issue affecting files accessible to the flatpak or _flatpak system user, and CVE-2026-96283, which could prevent cancellation of another user's flatpak-system-helper pull.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.