How a Simple "Hello World" Flatpak App Escapes the PipeWire Sandbox to Execute Arbitrary Code
The analysis of CVE‑2026‑5674 reveals that PipeWire’s PulseAudio compatibility layer contains three independent flaws—a missing cookie verification, default‑enabled module loading, and unrestricted dlopen() paths—that together let a sandboxed Flatpak app with only audio permission write files, launch desktop applications, and run arbitrary code on the host.
