in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. (CVE-2024-32462)
Flatpak versions prior to 1.10.9, 1.12.9, 1.14.6, and 1.15.8 contain a vulnerability allowing a malicious or compromised Flatpak app to execute arbitrary code outside its sandbox. This occurs due to improper handling of the --command argument in flatpak run, which can be exploited via the org.freedesktop.portal.Background.RequestBackground interface to pass arguments directly to bubblewrap (bwrap), enabling sandbox escape. The vulnerability is addressed by passing the -- argument to bwrap to stop option processing, and mitigated in xdg-desktop-portal 1.18.4 by restricting command creation. Patches are available in the specified fixed versions.
AI Analysis
Technical Summary
CVE-2024-32462 affects Flatpak, a Linux sandboxing system for desktop applications. In affected versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app can escape its sandbox by exploiting the --command argument of flatpak run. Specifically, it is possible to pass bubblewrap (bwrap) arguments such as --bind through the portal interface org.freedesktop.portal.Background.RequestBackground, which converts these into commands that bypass sandbox restrictions. The vulnerability is mitigated by ensuring bwrap stops processing options after a -- argument, a feature supported since bubblewrap 0.3.0, and by xdg-desktop-portal 1.18.4 restricting command creation. Red Hat has issued patches for affected versions, and the vulnerability is tracked under RHSA-2024:3980.
Potential Impact
A malicious or compromised Flatpak application can execute arbitrary code outside its intended sandbox environment, potentially leading to full system compromise or unauthorized access to system resources. This breaks the core security guarantees of Flatpak sandboxing. The CVSS 3.1 base score is 8.4, indicating high impact on confidentiality and integrity with low attack complexity and no user interaction required.
Mitigation Recommendations
A patch is available and should be applied by upgrading Flatpak to versions 1.10.9, 1.12.9, 1.14.6, or 1.15.8 or later. Additionally, upgrading xdg-desktop-portal to version 1.18.4 or later mitigates the vulnerability by restricting command creation. Red Hat Enterprise Linux 7 users should apply the security update RHSA-2024:3980. No further action is required beyond applying these official fixes.
in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. (CVE-2024-32462)
Description
Flatpak versions prior to 1.10.9, 1.12.9, 1.14.6, and 1.15.8 contain a vulnerability allowing a malicious or compromised Flatpak app to execute arbitrary code outside its sandbox. This occurs due to improper handling of the --command argument in flatpak run, which can be exploited via the org.freedesktop.portal.Background.RequestBackground interface to pass arguments directly to bubblewrap (bwrap), enabling sandbox escape. The vulnerability is addressed by passing the -- argument to bwrap to stop option processing, and mitigated in xdg-desktop-portal 1.18.4 by restricting command creation. Patches are available in the specified fixed versions.
CVSS v3.1
Score 8.4high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-32462 affects Flatpak, a Linux sandboxing system for desktop applications. In affected versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app can escape its sandbox by exploiting the --command argument of flatpak run. Specifically, it is possible to pass bubblewrap (bwrap) arguments such as --bind through the portal interface org.freedesktop.portal.Background.RequestBackground, which converts these into commands that bypass sandbox restrictions. The vulnerability is mitigated by ensuring bwrap stops processing options after a -- argument, a feature supported since bubblewrap 0.3.0, and by xdg-desktop-portal 1.18.4 restricting command creation. Red Hat has issued patches for affected versions, and the vulnerability is tracked under RHSA-2024:3980.
Potential Impact
A malicious or compromised Flatpak application can execute arbitrary code outside its intended sandbox environment, potentially leading to full system compromise or unauthorized access to system resources. This breaks the core security guarantees of Flatpak sandboxing. The CVSS 3.1 base score is 8.4, indicating high impact on confidentiality and integrity with low attack complexity and no user interaction required.
Mitigation Recommendations
A patch is available and should be applied by upgrading Flatpak to versions 1.10.9, 1.12.9, 1.14.6, or 1.15.8 or later. Additionally, upgrading xdg-desktop-portal to version 1.18.4 or later mitigates the vulnerability by restricting command creation. Red Hat Enterprise Linux 7 users should apply the security update RHSA-2024:3980. No further action is required beyond applying these official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2024:3980
- Cve Count
- 1
Threat ID: 6a3da1f44853345fc1833bdb
Added to database: 06/25/2026, 21:47:32 UTC
Last enriched: 09/10/2026, 14:42:03 UTC
Last updated: 09/10/2026, 19:36:48 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.