Omarchy Shipped Its Default User in the docker Group, Making Every Desktop Process Root
0xcc.io / Hacker News·medium signal
A disclosure published August 30 showed that Omarchy put its default user in the Linux docker group, so any process in the desktop session could ask the root-owned Docker daemon to mount arbitrary host paths into a root container and execute as root, with no password, sudo, or prompt. It was tested on the latest 3.x ISO (3.8.4) and everything before 4.0.1. The fix is in 4.0.1 and went through responsible disclosure first, but it is a clean reminder that docker-group membership is root equivalence on any distro that hands it out by default.