Since that post was'nt available for me atm, just reposting relevant Github blog : 1-Click RCE on GNOME
The TL;DR
libcue is a library used for parsing cue sheets—a metadata format for describing the layout of the tracks on a CD. it’s used by tracker-miners: an application that’s included with GNOME.The index is automatically updated when you add or modify a file in certain subdirectories of your home directory, in particular including ~/Downloads. To make a long story short, that means that inadvertently clicking a malicious link is all it takes for an attacker to exploit CVE-2023-43641 and get code execution on your computer.
I haven't used gnome in a while and decided to check it out again. I noticed that even though I've set the theme to dark apps like nautilus and gnome-control-center are always light-themed. Is that their intended behavior? If not, any ideas on what's wrong?
gtk3 apps need the old themeing from the tweaks app. The new option in settings only applies to gtk4 apps. Or something like that. So the theme option not affecting some apps is expected. You have to change to dark in the Tweaks app as well for backward compatibility.
No they are official arch linux packages. There are no flatpak or snap packages on this system. The only AUR packages that could influence appearance on this system are the adwaita-qt* packages, but these should have no effect at all on gnome apps.
If this is not a known issue, I guess I might have outdated options in config files or the dconf database. I'll do a cleanup and see if it fixes it.
I have two broken extensions: pop-shell and pano clipboard manager. I'll miss pop-shell for automatic tiling big time. The other alternatives suck in comparison 😭😭😭