Skip to content

fix(security): prevent host credential exfiltration in bwrap and Seatbelt extension sandbox - #1381

Merged
ZhuchkaTriplesix merged 1 commit into
devfrom
issue/1376-prevent-sandbox-credential-exfiltration
Oct 10, 2026
Merged

ZhuchkaTriplesix merged 1 commit into
devfrom
issue/1376-prevent-sandbox-credential-exfiltration

Conversation

@ZhuchkaTriplesix

Copy link
Copy Markdown
Member

Closes #1376

Summary

  • Linux (bwrap): Masks host /home directory by mounting --tmpfs /home right after root --ro-bind / /. This prevents untrusted or compromised plugin drivers with network access from reading and exfiltrating SSH keys (~/.ssh), cloud credentials (~/.aws, ~/.config/gcloud), shell histories, and session databases. The extension root (if inside home) is re-bound afterwards.
  • macOS (Seatbelt): Replaces unrestricted file access with an explicit (deny file-read* (subpath "/Users")) rule and allows read access to scratchPath and extensionRoot specifically.
  • Tests: Added assertions in sandbox_process_runner_test.dart verifying that host home read access is masked in bwrap args and denied in Seatbelt profiles.

@github-actions github-actions Bot added bug Something isn't working stability Theme parser epic label: stability core Core library logic and services P1 High priority / Core capability labels Oct 10, 2026
@ZhuchkaTriplesix
ZhuchkaTriplesix merged commit 18b53e4 into dev Oct 10, 2026
13 checks passed
@ZhuchkaTriplesix
ZhuchkaTriplesix deleted the issue/1376-prevent-sandbox-credential-exfiltration branch October 11, 2026 15:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working core Core library logic and services P1 High priority / Core capability stability Theme parser epic label: stability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant