A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-08 22:17
Updated : 2026-07-14 15:16
NVD link : CVE-2026-10037
Mitre link : CVE-2026-10037
CVE.ORG link : CVE-2026-10037
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
