
2 more related to Flatpak: xdg-desktop-portal: Trashing of arbitrary host files https://www.openwall.com/lists/oss-security/2026/04/10/14 CVE-2026-34080: xdg-dbus-proxy: Eavesdrop filter bypass allows message interception https://www.openwall.com/lists/oss-security/2026/04/10/15 a typical attacker would be a malicious or compromised Flatpak app
Post summary
OpenWall disclosed two new Flatpak‑related CVEs, detailing their impact (file trashing and message interception), but no PoC, exploit, or remediation is provided.


