https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-vjp5-hjfm-7677
Codean Labs reported that a D-Bus match rule parsing bug in xdg-dbus-proxy allows bypassing the proxy's eavesdropping restrictions. In practice xdg-dbus-proxy is mainly used by Flatpak, so a typical attacker would be a malicious or compromised Flatpak app.
The impact is that clients can read D-Bus messages on the session bus that they should not have had access to. This is fixed in xdg-dbus-proxy 0.1.7.
