SB20260827143 - Link following in Bubblewrap
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Link following (CVE-ID: N/A)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to write files outside the sandbox.
The vulnerability exists due to improper link resolution before file access in the bubblewrap sandbox setup logic when creating files or directories on attacker-controlled filesystem content. A local user can use symlinks that redirect through /oldroot to write files outside the sandbox.
This issue occurs during sandbox setup before anything is running inside the sandbox, and exploitation requires bubblewrap to create files on attacker-controlled filesystem content such as a malicious app image.
Remediation
Install update from vendor's website.