Junglewise Threat Intelligence

CVE-2026-96807: In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to writ

CVE-2026-96807 · Severity: medium · CVSS 4 · Published 2026-09-23