Heise.De Tails 7.6.2 Emergency Update Fixes Critical Flatpak Vulnerability
Article Content
- •Tails 7.6.2 patches a critical Flatpak vulnerability (CVE-2026-34078) with a CVSS score of 9.3.
- •The vulnerability allows attackers to escape the Tor Browser's sandbox and access sensitive files.
- •Users are strongly advised to update to Tails 7.6.2 to protect against potential data breaches.
The Tails Project has released an emergency update to Tails version 7.6.2 to address a critical security vulnerability in Flatpak, identified as CVE-2026-34078. This vulnerability, with a CVSS score of 9.3, allows attackers to escape the sandbox environment of the Tor Browser and access arbitrary files on the host system. Users of Tails, a Linux distribution designed for anonymous internet browsing, are at risk if they do not update, as the vulnerability could enable unauthorized access to sensitive information stored in persistent storage. The vulnerability requires an initial exploit of another flaw to gain control over the Tor Browser. The update includes the Flatpak package version 1.16.6, which mitigates this risk. Users are urged to download the updated images for USB, DVD, or VM installations. This follows a recent update to version 7.6.1 that addressed another Tor Browser vulnerability.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-34078 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Flatpak Vulnerabilities Allow Host File Access and Deletion Two critical vulnerabilities in Flatpak, identified as CVE-2026-34078 and CVE-2026-34079, were discovered, allowing malicious applications to access files outside their sandbox or delete arbitrary files on the host system. These vulnerabilities stem from improper path validation in sandbox-expose options and when…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…