E-Ink News Daily

Back to list

Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

QubesOS disclosed a critical arbitrary code execution vulnerability (QSB-118) in its copy-to-VM error reporting backchannel, which could allow a compromised VM to execute code on the destination VM. This flaw undermines QubesOS's core security-isolation model, as inter-VM communication channels are fundamental to the system's design. The vulnerability has been addressed in an updated release.

Background

QubesOS is a security-focused operating system that uses Xen-based virtualization to isolate applications and services into separate VMs called 'qubes.' Its threat-model relies heavily on secure inter-VM communication channels. This vulnerability directly targets one of those foundational communication mechanisms.

Source
Hacker News (RSS)
Published
Aug 30, 2026 at 04:51 PM
Score
8.0 / 10