Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, it says right in the CVE

> allowed a remote attacker to execute arbitrary code *inside the sandbox*



So then what's the big deal? If you had JavaScript turned off it would allow code to run in the sandbox anyway?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: