THREATOPS
THREAT OPSThreat News › Escaping Linux Sandboxes via PipeWire (CVE-2026-5674)

Escaping Linux Sandboxes via PipeWire (CVE-2026-5674)

medembracetheredPublished 2026-07-28

<p>This post walks through a sandbox escape from a Flatpak application via PipeWire that got fixed in July 2026. The vulnerability was discovered using my automated research pipeline using <code>Claude Code</code> and <code>Opus 4.6</code> back then early April 2026. It was an exciting find, because this my first bug submitted to Red Hat.</p> <p><strong>Claude Code was also excited finding this:</

Indicators of compromise

Original source: https://embracethered.com/blog/posts/2026/pipewire-flatpak-linux-sandbox-escape-cve-2026-5674/