Impact
The vulnerability in xdg-dbus-proxy causes it to ignore configured path, interface and member restrictions when filtering D‑Bus broadcast messages. As a result, a sandboxed Flatpak application can intercept broadcast signals on the D‑Bus session and AT‑SPI buses that are intended to be private, potentially exposing sensitive information to unauthorized applications. The flaw is an access‑control weakness, classified as CWE‑284. The impact is primarily the disclosure of confidential data that should have been protected by the restrictions.
Affected Systems
Red Hat Enterprise Linux 9 and 10 systems running xdg‑dbus‑proxy versions 0.1.6 and 0.1.7 are susceptible to this flaw. All other versions are unaffected. Users running these specific package releases should consider the vulnerability
Risk and Exploitability
The vulnerability has a CVSS score of 3.2, indicating low severity, and an EPSS score of < 1%, indicating a very low but nonzero exploitation probability. It is not listed in CISA KEV. The attack is likely to be carried out locally by a compromised or malicious Flatpak application that has access to the session bus. Because the vulnerability allows privileged signal interception without additional privileges, it can be leveraged by any user running a compromised or misbehaving sandboxed app, but it does not provide system‑wide escalation or remote code execution. Accordingly, the risk is low‑to‑moderate and mitigation is recommended promptly.
OpenCVE Enrichment