Skip to main content
EPSS 0.5%top 58%

in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. (CVE-2024-32462)

0
Medium
Published: 04/18/2024 (04/18/2024, 18:15:00 UTC)
Source: GCVE Database
Product: flatpak

Description

Flatpak versions prior to 1.10.9, 1.12.9, 1.14.6, and 1.15.8 contain a vulnerability allowing a malicious or compromised Flatpak app to execute arbitrary code outside its sandbox. This occurs due to improper handling of the --command argument in flatpak run, which can be exploited via the org.freedesktop.portal.Background.RequestBackground interface to pass arguments directly to bubblewrap (bwrap), enabling sandbox escape. The vulnerability is addressed by passing the -- argument to bwrap to stop option processing, and mitigated in xdg-desktop-portal 1.18.4 by restricting command creation. Patches are available in the specified fixed versions.

CVSS v3.1

Score 8.4high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Affected software

redhat/flatpak
pkg:rpm/redhat/flatpak
Affected versions
=1.0.9-13.el7_9

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 14:42:03 UTC

Technical Analysis

CVE-2024-32462 affects Flatpak, a Linux sandboxing system for desktop applications. In affected versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app can escape its sandbox by exploiting the --command argument of flatpak run. Specifically, it is possible to pass bubblewrap (bwrap) arguments such as --bind through the portal interface org.freedesktop.portal.Background.RequestBackground, which converts these into commands that bypass sandbox restrictions. The vulnerability is mitigated by ensuring bwrap stops processing options after a -- argument, a feature supported since bubblewrap 0.3.0, and by xdg-desktop-portal 1.18.4 restricting command creation. Red Hat has issued patches for affected versions, and the vulnerability is tracked under RHSA-2024:3980.

Potential Impact

A malicious or compromised Flatpak application can execute arbitrary code outside its intended sandbox environment, potentially leading to full system compromise or unauthorized access to system resources. This breaks the core security guarantees of Flatpak sandboxing. The CVSS 3.1 base score is 8.4, indicating high impact on confidentiality and integrity with low attack complexity and no user interaction required.

Mitigation Recommendations

A patch is available and should be applied by upgrading Flatpak to versions 1.10.9, 1.12.9, 1.14.6, or 1.15.8 or later. Additionally, upgrading xdg-desktop-portal to version 1.18.4 or later mitigates the vulnerability by restricting command creation. Red Hat Enterprise Linux 7 users should apply the security update RHSA-2024:3980. No further action is required beyond applying these official fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2024:3980
Cve Count
1

Threat ID: 6a3da1f44853345fc1833bdb

Added to database: 06/25/2026, 21:47:32 UTC

Last enriched: 09/10/2026, 14:42:03 UTC

Last updated: 09/10/2026, 19:36:48 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses