Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

KDE Plasma Affected By Arbitrary Code Execution To Break Sandboxes With "Open New Window"

Дата публикации: 02-07-2026 11:51:00

A security disclosure has been made public today for a yet-to-be-patched arbitrary code execution vulnerability with the KDE Plasma desktop...

Основное содержимое страницы с новостью.

KDE

A security disclosure has been made public today for a yet-to-be-patched arbitrary code execution vulnerability with the KDE Plasma desktop.

Open-source developer Kimiblock discovered an arbitrary code execution exploit for Plasma that can break sandboxes. The issue was reported to upstream KDE developers via their security email address and reportedly ignored and unpatched in the latest Plasma 6.7 desktop. Following the typical 90 day embargo, the exploit including proof-of-concept code has been published.

KDE open new window

This web page outlines the arbitrary code execution and the possibility of malicious sandboxed apps such as via Flatpak could spawn arbitrary binaries on the host via Plasma's "Open New Window" action.

"While accidently middle clicking on the task bar (it would invoke “Open New Window” by default for a specific app), the app launched a new window as expected, yet it did not seem to remember my saved login credentials, nor did it use any of modified settings. Upon closer inspection, combining the PID obtained from KWin Debug Console and control groups + rootfs info from procfs, a complete sandbox escape has surfaced.
...
So it was clear, there is a complete sandbox escape when I accidently triggered a middle-click inside the virtual machine."

The issue is yet to be patched and with no follow-ups from the KDE security team, the proof of concept code and details were made public today following the 90 day window. All the details for those interested via the disclosure page.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1KDE Plasma 6.7.2 Brings Fix For Most Common KWin Crash, Better Chromium Video Playback0730-06-2026
2XWayland 24.1.13 Released To Fix Two More Security Issues In The X.Org Codebase0508-07-2026
3Рассекречена новая версия Windows0503-07-2026
4KDE Linux Introduces "Developer Mode" Option, Easier Log Collection0501-07-2026
5Nissan blames Oracle vulnerability for data breach0730-06-2026
6New U-Boot flaws could enable stealthy firmware attacks-2710-07-2026
7Linux Kernel Developers Again Discussing AI Agent Attribution - Potentially Dropping It0702-07-2026
8COSMIC Epoch 1.2 Desktop Fixes Flickering Issues For Intel Graphics0530-06-2026
9Critical "Gitea" vulnerability exploited-5706-07-2026
10New GitHub Zero-Day Exposed Developer Tokens to Attackers-5704-06-2026

Классификация: Информация. Схожих патентов: 0. Схожих новостей: 10. Тональность: -2. Информативность: 7. Источник: www.phoronix.com.