Columnist adopts Vivaldi on Linux

A ZDNET opinion column published July 22, 2026 detailed the author's decision to make Vivaldi his default web browser on Linux. The piece walks through the reasoning behind the switch and considers how the browser fits with day-to-day Linux desktop workflows.
Linux security context: Ubuntu snap-confine flaw
Separately, security researchers at the Qualys Threat Research Unit publicly disclosed a high-severity local privilege escalation vulnerability in Ubuntu's snap-confine component, tracked as CVE-2026-8933. The flaw affects Ubuntu Desktop 24.04, 25.10 and 26.04 and could allow an unprivileged user to obtain full root access on default installations. Canonical released patches through its Ubuntu Security Team following a coordinated disclosure process, with the public release coordinated for July 21, 2026.
How the vulnerability works
According to the Qualys advisory, the flaw stems from a security-hardening change that introduced a race condition during sandbox initialization. The exploit chains two concurrent race conditions to achieve arbitrary file creation, enabling an attacker who drops a malicious .rules file in /run/udev/rules.d to trigger arbitrary command execution with full root privileges through the systemd-udevd daemon. Mounting and unmounting any FUSE filesystem is sufficient to trigger udevd to process the new rule.
Discovery and disclosure timeline
The Qualys TRU sent its advisory and exploit to the Ubuntu Security Team in April 2026. Canonical's team subsequently sent patches to the linux-distros mailing list in mid-July, with Qualys following one day later. Qualys credited Eduardo Barretto and Zygmunt Krynicki at Canonical for rapid coordination and patch review, and acknowledged the linux-distros community for collaboration in hardening the snap ecosystem.
Affected systems
Default installations of Ubuntu Desktop 26.04, codenamed Resolute Raccoon, and 25.10 are vulnerable and exploitable because they ship the set-capabilities version of /usr/lib/snapd/snap-confine. Default, up-to-date installations of Ubuntu Desktop 24.04 LTS are also vulnerable through the snapd snap package. Qualys published detection guidance for organizations looking to identify exposed systems.
Share this article







