GNOME Yelp Updated to Fix Flatpak Sandbox Escape Vulnerability
GNOME has released version 49.1 of its help viewer, Yelp, to address a critical security vulnerability that allowed for potential Flatpak sandbox escapes. This update follows a security audit conducted by Codean Labs, funded by Germany's Sovereign Tech Agency under its Sovereign Tech Resilience program. The vulnerability, related to a previous issue from last year involving arbitrary file reads, enables sandboxed applications to launch Yelp with malicious help files. These files can exploit overly permissive Content Security Policy (CSP) settings to exfiltrate arbitrary files from the host operating system to external web servers using CSS stylesheets embedded within SVG images. GNOME developer Michael Catanzaro highlighted the sophistication of this attack vector, noting it is more impactful than typical memory safety bugs. The issue was reported three months prior to the release. This patch ensures that Flatpak applications cannot bypass sandbox restrictions through Yelp, significantly enhancing the security posture of GNOME desktop environments against data exfiltration threats.
Wire timeline
GNOME Yelp Updated to Fix Flatpak Sandbox Escape Vulnerability
GNOME has released version 49.1 of its help viewer, Yelp, to address a critical security vulnerability that allowed for potential Flatpak sandbox escapes. This update follows a security audit conducted by Codean Labs, funded by Germany's Sovereign Tech Agency under its Sovereign Tech Resilience program. The vulnerability, related to a previous issue from last year involving arbitrary file reads, enables sandboxed applications to launch Yelp with malicious help files. These files can exploit overly permissive Content Security Policy (CSP) settings to exfiltrate arbitrary files from the host operating system to external web servers using CSS stylesheets embedded within SVG images. GNOME developer Michael Catanzaro highlighted the sophistication of this attack vector, noting it is more impactful than typical memory safety bugs. The issue was reported three months prior to the release. This patch ensures that Flatpak applications cannot bypass sandbox restrictions through Yelp, significantly enhancing the security posture of GNOME desktop environments against data exfiltration threats.
Phoronix