Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
mikeweiss
17 days ago
|
parent
|
context
|
favorite
| on:
Actively exploited sandbox RCE in all Chromium ver...
Isn't this exactly why there is a sandbox? What can the RCE actually do or obtain within the sandbox?
socalgal2
16 days ago
|
next
[–]
Yes, it says right in the CVE
> allowed a remote attacker to execute arbitrary code *inside the sandbox*
mikeweiss
16 days ago
|
parent
|
next
[–]
So then what's the big deal? If you had JavaScript turned off it would allow code to run in the sandbox anyway?
nikanj
16 days ago
|
prev
|
next
[–]
Doesn’t any <script> tag let you run arbitrary code inside a sandbox anyway?
lima
15 days ago
|
parent
|
next
[–]
Inside the JS sandbox, not the browser's outer containment sandbox.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: