A corrective update for the Flatpak 1.10.2 framework is available, which addresses a vulnerability (CVE-2021-21381) that allows the package author of an application to bypass the established sandbox isolation and gain access to files in the host system. The issue appears starting from the 0.9.4 release.
The vulnerability is caused by an error in the implementation of the file access redirection function, which allows resources in an external file system to be accessed through manipulation of the .desktop file, which the running application is not permitted to access. When files with the tags «@@» and «@@u» are added in the Exec field, flatpak considers that the specified target files were explicitly indicated by the user and automatically grants access to these files in the sandbox. This vulnerability can be exploited by authors of malicious packages to gain access to external files, despite appearing to run in isolation mode.
Source: opennet.ru
