Executive brief
Wine, a software layer used to run Windows applications on Linux, contains a configuration that automatically registers it as the default handler for Windows executable files (.exe, .msi, .bat). This behavior allows malicious software trapped inside a security sandbox (like Flatpak or Snap) to trick the system into running a program outside of that sandbox. If exploited, an attacker could bypass security restrictions to gain full access to the user's files and system.
Technical details
Wine ships a .desktop file that registers 'wine start /unix' as the MIME handler for 'application/x-ms-dos-executable', 'application/x-msi', and 'application/x-bat'. This violates the security recommendation that MIME handlers should only open files rather than execute them. Sandboxed environments like Flatpak and Snap often allow access to D-Bus interfaces such as 'org.freedesktop.portal.OpenURI' or 'org.freedesktop.FileManager1', which can be used to request the host system to open a file. An attacker within a sandbox can write a malicious Windows executable to a shared directory and trigger these interfaces; if Wine is the sole handler, the host system will execute the file unsandboxed with the user's full privileges. The Wine project has disputed this as a vulnerability, citing usability concerns and the lack of a universal 'binfmt-misc' alternative.
Affected products
- WineHQ Wine All versions including 11.9
Timeline
- 2026-05-18: disclosed: Initial report to WineHQ bug tracker and oss-security mailing list.
- 2026-05-24: advisory: CVE-2026-48831 assigned and published.