BleachBit 6.0.4 Fixes Secure Wiping Issues with Windows Cluster Erasure

www.news4hackers.com-bleachbit-6-0-4-fixes-secure-wiping-issues-with-windows-cluster-erasure-bleachbit-6-0-4-fixes-secure-wiping-issues-with-windows-cluster-erasure

BleachBit 6.0.4 addresses secure deletion issues on Windows by resolving cluster omission problems.

BleachBit 6.0.4 Overview

BleachBit 6.0.4 addresses secure deletion issues on Windows by resolving cluster omission problems The open source utility BleachBit released version 6.0.4, expanding its capabilities to remove caches, browser data, and files across Windows, Linux, and macOS. Earlier versions of the software failed to fully erase sensitive files on Windows due to incomplete cluster wiping. This occurred because Windows typically splits files into noncontiguous clusters when storage space is fragmented, leaving residual data in unprocessed areas. The update does not specify which prior versions were affected or quantify how much data remained, making it impossible to determine which files were at risk based on version numbers. Once a file is deleted, re-shredding is no longer possible, necessitating the wiping of free space on impacted drives.

Secure Deletion Enhancements

Chromium- and Firefox-based browsers maintain a dynamic HSTS list that stores sites requiring HTTPS connections. This list can be modified by visited websites, creating persistent tracking identifiers that survive standard cookie removal. BleachBit now removes this dynamic HSTS data from six Chromium-based browsers and Zen, a Firefox variant. The update also restricts file shredding operations from targeting the current working directory or its parent, preventing path collapse vulnerabilities. On POSIX systems, critical directories such as /, /proc, /sys, and /run are protected from deletion even when the keep list is empty.

Security and File Management Updates

Wiping operations no longer follow symbolic links in wipe_write or wipe_contents functions, as Windows blocks file deletion through symlinks. Truncation processes now reject reparse points, while clipboard-pasted files with malformed URIs are skipped instead of processed. The tool issues warnings when attempting to shred drives with world-writable permissions, as this poses security risks. The Windows build now uses absolute paths for system commands like ipconfig and taskkill to prevent execution of malicious binaries via the search path.

Code and System Security Improvements

Untrusted cleaner definitions are restricted from executing process or winreg actions, and POSIX systems no longer load cleaner files in world-writable directories. XML parsing mechanisms now block Document Type Definitions (DTDs), and update checks process XML as bytes to maintain this restriction even for encoded documents. Insecure URLs for winapp2 and update checks are rejected, and wildcard counts in winapp2.ini patterns are limited to prevent regex-based denial-of-service attacks.

New Features and Tools

Security enhancements include hardened SQLite and URI construction in Special.py, migration of Windows builds and tests to GitHub Actions, implementation of a CodeQL workflow for bug detection, and static analysis integration into the CI/CD pipeline. A code injection vulnerability during CI translation updates was also resolved. New features include cleaners for Android Studio, Gradle cache, fish shell, Zsh, and Python command history. These tools target history files that may contain credentials or sensitive input.

macOS Support and Additional Updates

The Claude cleaner now removes top-level log files. macOS support is in early stages but functional, featuring a Safari cleaner, browser-specific tools, full command-line access, and a GUI under development. BleachBit alerts users when Full Disk Access is disabled, provides native notifications, respects keyboard shortcuts like Cmd+Q, and removes empty folders during trash cleanup. Additional security updates include patches for critical vulnerabilities in N-central (CVE-2026-86218), exploitation of RouterOS flaws in MikroTik devices, and ransomware negotiation frameworks evolving into formalized processes.

Phishing campaigns targeting Trezor users followed a shipping-partner data breach, while a zero-click WeChat worm demonstrated account hijacking capabilities through single calls.


Blog Image

About Author

en_USEnglish