Live data from Hacker News

Actively exploited sandbox RCE in all Chromium versions

nvd.nist.gov

1–10 of 524 posts

Re: Actively exploited sandbox RCE in all Chromium versions

#5

Brave is beating GrapheneOS on update timeliness: https://github.com/GrapheneOS/Vanadium/releases https://github.com/brave/brave-browser/releases Only if you use Nightly wait maybe not.

The release version just now updated to 152.0.7977.83 which has the fix.

Re: Actively exploited sandbox RCE in all Chromium versions

#6
post #3
post #2

Only a score of 8.8?

RCE inside sandbox, so requires chaining with another 0day.

What exactly does "RCE inside sandbox" describe that goes beyond "the webpage can supply arbitrary JavaScript and the JavaScript engine executes it", but is still isolated from the system?

Re: Actively exploited sandbox RCE in all Chromium versions

#7
post #6
post #3

Earlier quoted context omitted.

RCE inside sandbox, so requires chaining with another 0day.

What exactly does "RCE inside sandbox" describe that goes beyond "the webpage can supply arbitrary JavaScript and the JavaScript engine executes it", but is still isolated from the system?

It means it can execute arbitrary machine code in the sandbox.

Re: Actively exploited sandbox RCE in all Chromium versions

#9

Brave is beating GrapheneOS on update timeliness: https://github.com/GrapheneOS/Vanadium/releases https://github.com/brave/brave-browser/releases Only if you use Nightly wait maybe not.

Is graphene even affected? JIT is disabled in default configurations.

Re: Actively exploited sandbox RCE in all Chromium versions

#10
As somebody who prefers to browse with JS off whenever possible, there's something absurd about the balance everyone takes for granted between (A) your personal safety against a devastating hack by malicious code and (B) surveillance advertising.

"Sorry, but to enter this shop you need to take one of the used syringes from that pile some dude delivers every day and poke yourself with it."

Post reply on HN