Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, it says right in the CVE

> allowed a remote attacker to execute arbitrary code *inside the sandbox*



So then what's the big deal? If you had JavaScript turned off it would allow code to run in the sandbox anyway?




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: