Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Isn't this exactly why there is a sandbox? What can the RCE actually do or obtain within the sandbox?


Yes, it says right in the CVE

> allowed a remote attacker to execute arbitrary code *inside the sandbox*


So then what's the big deal? If you had JavaScript turned off it would allow code to run in the sandbox anyway?


Doesn’t any <script> tag let you run arbitrary code inside a sandbox anyway?


Inside the JS sandbox, not the browser's outer containment sandbox.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: