Does Flatpak weaken Chromium/Firefox's sandbox?

Tails (an official tor project parter) runs tor browser in a fake flatpak that allows access to unprivileged namespaces because otherwise it would weaken its sandbox.

Major QubesOS dev says chromium sandbox is weaker when ran in a flatpak. The whole issue is interesting and references this thread and Cromite’s dev’s take that flatpak does weaken the chromium sandbox. Rustysnake (a frequent Firejail, Bubblejail, and Flatpak contributor) agrees.

Madaidan (former Whonix/Kicksecure security researcher) agrees

Vivaldi dev voices similar concerns and says they will review the sandbox and make the package official if they don’t find it significantly weaker. The package is still unofficial.

As a result, secureblue has been investigating sandboxing chromium directly with bubblewrap

Related

6 Likes