PipeWire Flaw Lets Attackers Escape Linux Sandboxes via Audio Access
A security researcher has disclosed a sandbox escape vulnerability (CVE-2026-5674) affecting PipeWire, the audio server now used by default on most modern Linux desktops, including Fedora, Ubuntu 24.04+ and Debian 13. PipeWire replaced the older PulseAudio system while maintaining compatibility with it, and many sandboxed apps request basic audio access to function normally.
The research found that a simple app with standard audio permissions could break out of its sandbox and gain full access to a user's desktop, files and credentials. The issue stems from three combined problems: PipeWire fails to properly validate the authentication "cookie" that PulseAudio clients are meant to present, a setting that allows any connected client to load additional software modules is enabled by default, and one of those modules can be tricked into loading arbitrary code without any checks on where that code comes from. Together, these gaps allow a program with only audio permissions to run code outside the sandbox. The same attack method could apply to other sandboxing technologies, such as Docker, that connect to PipeWire in a similar way.
The researcher noted this flawed cookie-check behaviour has existed since PipeWire's PulseAudio compatibility layer was first built, and the module-loading setting was only added in May 2024, still defaulting to an unsafe configuration. This is described as similar in pattern to a previously known FFmpeg vulnerability.