Any app on the desktop could become root, no password asked.

Anyone running Omarchy inherited that risk the moment they installed it, without being told.

A default Docker group membership let any user process command the root-owned Docker daemon to mount and read the entire filesystem.

Omarchy shipped a fix in version 4.0.1; users who haven’t updated remain exposed.

How each outlet framed it
Hacker News
explains docker socket vulnerability enabling session-level root escalation via docker group membership in default config

Sources: Hacker News