Skip to content

fix(security): prevent host credential exfiltration in bwrap and Seatbelt extension sandbox #1376

Description

@ZhuchkaTriplesix

Problem

In SandboxLaunchCommand (lib/core/extensions/sandbox/sandbox_launch_command.dart, lines 101–111, 162–175):

  1. Linux (bubblewrap):
final args = <String>[
  '--unshare-all',
  '--share-net',
  '--die-with-parent',
  '--new-session',
  '--ro-bind', '/', '/',
  '--bind', scratchPath, scratchPath,
  '--chdir', scratchPath,
];

--ro-bind / / mounts the entire root filesystem read-only inside the container.
Combined with --share-net (which is required for database drivers to communicate with database servers), an untrusted or compromised extension driver can read:

  • ~/.ssh/ (SSH private keys and known hosts)
  • ~/.aws/credentials, ~/.config/gcloud/
  • ~/.bash_history, ~/.zsh_history
  • Local profile databases and browser session stores
    and exfiltrate them over the network.
  1. macOS (Seatbelt / sandbox-exec):
(version 1)
(deny default)
(allow process*)
(allow sysctl-read)
(allow mach-lookup)
(allow network*)
(allow file-read*)
(allow file-write* (subpath "$scratchPath"))

(allow file-read*) allows reading every file across the host filesystem. Combined with (allow network*), any extension process can read and exfiltrate user files without restrictions.

Scope

  • In Linux bwrap configuration:
    • Mount system library paths (/usr, /lib, /lib64, /etc/ssl, /etc/resolv.conf, /dev, /proc) rather than full /, OR mask /home via --tmpfs /home (or --tmpfs $HOME), binding only the specific extension directory and scratch directory.
  • In macOS Seatbelt profile:
    • Replace global (allow file-read*) with permissions restricted to system libraries and the extension bundle/scratch directory, explicitly denying (deny file-read* (subpath "/Users")) or sensitive home paths (~/.ssh, ~/Library/Keychains).
  • Add tests in sandbox_launch_command_test.dart verifying that host home directory read access is masked in both Linux and macOS launch commands.

Activity

  1. added
    bugSomething isn't working
    stabilityTheme parser epic label: stability
    coreCore library logic and services
    P1High priority / Core capability
    on Oct 10, 2026
  2. ZhuchkaTriplesix commented on Oct 11, 2026

    @ZhuchkaTriplesix
    MemberAuthor

    Done in #1381 (merged into dev).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1High priority / Core capabilitybugSomething isn't workingcoreCore library logic and servicesstabilityTheme parser epic label: stability

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions