Security Flaw in GNOME Shell Extensions by GNOME
CVE-2017-8288
8.1HIGH
What is CVE-2017-8288?
The GNOME Shell vulnerabilities arise from improper handling of extensions that fail to reload, which may leave them active in the lock screen. This could allow unauthorized observers to run applications without interaction, reveal information like active applications or music playlists, and potentially execute arbitrary commands depending on the extensions a user has enabled. The flaw is linked to insufficient exception handling in the JavaScript component responsible for managing extensions.