What's wrong with this entry?
Better handling of symlinked write paths in the Linux sandbox.
- Skips symlink write paths that point outside expected locations
- Logs warnings when write paths cannot be resolved
- Prevents potential sandbox escapes via symlink manipulation
Sandbox symlink handling (search for "Skipping symlink write path pointing outside expected location")
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.