D-Bus Broadcast Message Filtering Flaw in xdg-dbus-proxy from Red Hat
CVE-2026-93676
3.2LOW
What is CVE-2026-93676?
The xdg-dbus-proxy has a vulnerability where it fails to properly filter D-Bus broadcast messages, allowing sandboxed Flatpak applications to intercept broadcast signals on both the D-Bus session bus and the AT-SPI bus. This flaw compromises configured restrictions related to paths, interfaces, and members, potentially allowing malicious applications to access sensitive information that should be protected, leading to unauthorized data exposure.