The agency launched an investigation in February 2020 after receiving multiple complaints from consumer rights organizations. It examined three Google features that were active during the GDPR application period from May 25, 2018, through February 4, 2020.

The features cover permissions that allowed Google to process users’ web and app activity, location history, and location accuracy data:

Web and App Activity – A setting for Google Account holders that allows Google to process activity across its services, potentially including browsing history, search history, and location data.
Location History – An opt-in service that tracks users carrying compatible mobile devices. It can infer visited places, activities, and routes, and displays this information through a private Google Maps Timeline, even when the user is not actively using a Google service.
Location Accuracy – An Android feature that helps a device determine its position more accurately than GPS alone. It is available regardless of whether the user has a Google Account.

The DPC found that Google processed location data through Web & App Activity and Location History without meeting the GDPR’s requirements. At the same time, the company failed to demonstrate compliance with GDPR principles when processing personal data through Location Accuracy.

 

GNOME Boxes lead developer Felipe Borges has been overhauling the application with a major rewrite and today announced the new beta release. GNOME Boxes has migrated to using the GTK4 toolkit and libadwaita. The new GNOME Boxes code can also handle installing Microsoft Windows 11 now without needing any manual workarounds for Secure Boot or TPM requirements.

The new GNOME Boxes code also introduces a VSOCK device for accessing VM contexts and other improvements. With the revamped GNOME Boxes, it's also shifting to a Flatpak-first and only model for distributing of new GNOME Boxes releases.

 

Fixes are available for 3 vulnerabilities reported in snapd, each with assigned CVE IDs and CVSS scores.

  • CVE-2026-8933, discovered by Qualys, allows local attackers to escalate privileges. It impacts default installations of Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. The CVSS 3.1 score assigned to the vulnerability is 7.8 (high).
  • CVE-2026-15226, discovered by Zygmunt Krynicki, Canonical team member, allows local attackers to escape snap confinement from confined root to unconfined root. The CVSS 3.1 score assigned to the vulnerability is 8.4 (high).
  • CVE-2024-5300 discovered by James Henstridge, Canonical team member, allows a sandboxed application to access hashed user passwords. This vulnerability impacts installations of Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS Ubuntu, 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS where systemd-userdbd is available. The CVSS 3.1 score assigned to the vulnerability is 5.6 (medium).

Affected releases

The following table lists the affected snaps. Revisions with patches will be updated as they are released.

Snap name Channel Remediation status
snapd latest/stable pending (2.76.1) publication
snapd fips-updates/stable not planned
core latest/stable pending

The snapd package distributed via the Ubuntu archive is also affected in the following releases. Fixes have been released as security updates.

Release Package Name Fixed Version
Xenial (16.04) snapd 2.61.4ubuntu0.16.04.1+esm4
Bionic (18.04) snapd 2.61.4ubuntu0.18.04.1+esm4
Focal (20.04) snapd 2.67.1+20.04ubuntu1~esm3
Jammy (22.04) snapd 2.76+ubuntu22.04.1
Noble (24.04) snapd 2.76+ubuntu24.04.1
Resolute (26.04) snapd 2.76+ubuntu26.04.3
view more: next ›