Live data from Hacker News

Zero-day CSS: CVE-2026-2441 exists in the wild

chromereleases.googleblog.com

241–242 of 242 posts

Re: Zero-day CSS: CVE-2026-2441 exists in the wild

#241
post #65

Earlier quoted context omitted.

Yes, but it's only a vulnerability if the app allows rendering untrusted HTML or visiting untrusted websites, which most Electron apps don't.

Lots of apps like slack and discord will show you an opengraph preview of a website if you post a link. I could of course be wrong but expect you could craft an exploit that just required you to be able to post the link - then it it would render the preview and trigger the problem. Secondly as a sibling pointed out lots of apps have html ads so if you show a malicious ad it could also trigger. I’m old enough to remem…

Open Graph is a standard for HTML meta tags. Apps like Slack and Discord just make a request to the given URL (locally or in their servers) and read those tags. Then they choose how that information should be displayed. No HTML injection occurs.

https://ogp.me

Re: Zero-day CSS: CVE-2026-2441 exists in the wild

#242
post #225

Earlier quoted context omitted.

I mean on the computer, and I haven't found a way to have it at the top.

Alright, now I'm doubly confused, since the search bar is typically on the address bar which is at the top of the screen. You might want to test a clean profile. Perhaps some customisation along the way changed things on your setup.

I mean to search within the page
Post reply on HN