3 ms·
I am very unfamiliar with electron and security in general. But generally I understand electron as a browser-like sandbox for desktop applications. Can someone
by samblogs 6y ago
I am very unfamiliar with electron and security in general. But generally I understand electron as a browser-like sandbox for desktop applications.
Can someone please explain how the "electronSafeIpc" might be implemented? Naively this functionality seems to be the very dangerous part of this exploit, and seems to be a workaround of electron's intent to sandbox your application?
- gorbypark 6y agoElectron uses an IPC to communicate between processes. Each process is like a thread, but really it’s more like a chrome tab. Most apps have at least two processes, main and renderer. The IPC passes JSON events between them. “ElectronSafeIpc” appears to be a Microsoft implemented function that is wrapping up the native IPC functions and is assumingly providing some sort of safety checks. I gather the safety checks weren’t good enough, so once one process is taken over, the researcher has managed to use the IPC to access the main process. That’s still sandboxed usually but...