Junglewise Threat Intelligence

CVE-2026-48831: Wine sandbox escape via Windows executable MIME handler registration

CVE-2026-48831 · Severity: info · CVSS 7.3 · Published 2026-05-24

Executive brief

Wine, a software layer used to run Windows applications on Linux, contains a configuration that automatically registers it as the default handler for Windows executable files (.exe, .msi, .bat). This behavior allows malicious software trapped inside a security sandbox (like Flatpak or Snap) to trick the system into running a program outside of that sandbox. If exploited, an attacker could bypass security restrictions to gain full access to the user's files and system.

Technical details

Wine ships a .desktop file that registers 'wine start /unix' as the MIME handler for 'application/x-ms-dos-executable', 'application/x-msi', and 'application/x-bat'. This violates the security recommendation that MIME handlers should only open files rather than execute them. Sandboxed environments like Flatpak and Snap often allow access to D-Bus interfaces such as 'org.freedesktop.portal.OpenURI' or 'org.freedesktop.FileManager1', which can be used to request the host system to open a file. An attacker within a sandbox can write a malicious Windows executable to a shared directory and trigger these interfaces; if Wine is the sole handler, the host system will execute the file unsandboxed with the user's full privileges. The Wine project has disputed this as a vulnerability, citing usability concerns and the lack of a universal 'binfmt-misc' alternative.

Affected products

  • WineHQ Wine All versions including 11.9

Timeline

  • 2026-05-18: disclosed: Initial report to WineHQ bug tracker and oss-security mailing list.
  • 2026-05-24: advisory: CVE-2026-48831 assigned and published.

References