From the article linked to in op (“Arbitrary code execution breaking sandboxes in KDE Plasma”):
This proof of concept demonstrates a mean for malicious sandboxed (Flatpak here, but any sandbox apply. With or without the security context support.) applications to impersonate and, more importantly, spawn arbitrary binaries on the host when user invokes Open New Window action.
Based on the fact that KWin could not associate the window to a real .desktop file, there must be something that still allows it to find a argv0 to execute.
So it is not only restricted to Flatpaks and only restricted to KWin?
Would be nice if the title of the topic would reflect that:
It’s only been proven with flatpaks, the other sandboxes are theoretical and should work the same so I’m going to leave that as flatpaks. I’ll adjust it to mention Plasma though.
Flatpak is the only one proven so far, and the one most likely to be used. Also, one should read the linked blog post, just as one should read PKGBUILDs
Based on the fact that KWincould not associate the window to a real .desktop file, there must be something that still allows it to find a argv0 to execute. I took a guess on /proc/PID/cmdline and it proved to be right.
This is not limited to spawning existing application instances outside of the sandbox. Since it just so happens that any process, including unprivileged ones can change it’s argv0
The topic tile includes the only sandboxed utility tested & proven so far, as well as the DE affected. Even though I use Xfce and have no flatpaks installed, it grabbed my attention and prompted me to read the blogpost.
At least, mentioning KWin being the culprit in breaching “any sandbox”, as says the article would bring the title somewhat in line with the content of the article.
Needless to mention (but I do it anyways), before my first post pointing that out, the title of the topic read:
Flatpak sandboxing breached
That’s a far cry away from what is discussed in the article.
This is a technical forum and not a YT channel making sensational “thumbnails” to get more clicks.
Call me pedant and “pricky one” , I couldn’t care less for you being condescending .
However, what I care for, is that it is fitting for the the title of the topics posted on a technical forum, worthy of its name or pretension, to be less “sensationalist” (and that on erroneous ground) and based more on facts.
Ah, I see. So the sharing of Technical information is a secondary goal, an afterthought of some sort?
Even so, shouldn’t this sharing of “Technical information” occur in such a way that it is in accordance with some facts. Out of the respect of it being “Technical” and “Information”.
That is my point, and I stand by it.
I don’t see any relevance in the “dichotomy” you are trying to create between “technical forum” and “a Friendly Community sharing Technical information”. That’s totally beside the point.
It is not about my happiness. My happiness (or lack thereof) is not conditioned by the title of a topic in a technical forum or should I say in a more nuanced way,
making a sensationalist, false claim.
By the way you changed it back to the worse. Just saying
I’m only pointing out that out of all the things I’ve heard about the Forum its never been called a “Technical” Forum it was alway’s advertised as a `Family Friendly Community. Community would suggest that not everyone is TECHNICAL.