Escaping Linux Sandboxes via PipeWire (CVE-2026-5674)
This post walks through a sandbox escape from a Flatpak application via PipeWire. The vulnerability was discovered using my automated research pipeline with Claude Code and Opus 4.6 back in April 2026. It was an exciting find, as this was the first bug I submitted to Red Hat.
Claude Code was also excited finding this:
Once discovered, I repro’d it manually to make sure it’s legit and then submitted it to Red Hat.