snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. snapd bug: https://bugs.launchpad.net/snapd/+bug/1910298 Upstream PR and commits: https://github.com/snapcore/snapd/pull/9897 https://github.com/snapcore/snapd/pull/10992 https://github.com/snapcore/snapd/commit/6bcaeeccd16ed8298a301dd92f6907f88c24cc85 (2.52) https://github.com/snapcore/snapd/commit/7d2a966620002149891446a53cf114804808dcca (2.54)