• Sources: primary, discussion
  • Summary: Omarchy added its default user to the Linux docker group, and on Arch the Docker daemon runs as root on /var/run/docker.sock, so any process in the desktop session could ask that daemon to mount the host filesystem into a root container. The researcher gives a proof of concept reading /etc/shadow through docker run -v /:/hostroot, and notes that supplementary groups are inherited, so browsers, editors, npm scripts and AI coding agents all held root without sudo or a prompt. Versions below 4.0.1 are affected, the report was tested on 3.8.4 and disclosed privately before publication, and the group membership was introduced on 2025-06-01 and removed on 2026-08-24.
  • Why it matters: A default desktop configuration turned every unprivileged process in the session into a path to full host compromise with no authentication step.

send feedback on this story