3 ms·
From the blog post: >In addition to targeting users via social engineering, we have also observed several cases where researchers have been compromised after v
by dotty- 6y ago
From the blog post:
>In addition to targeting users via social engineering, we have also observed several cases where researchers have been compromised after visiting the actors’ blog.
Aka, they were compromised after simply visiting a malicious blog. This is why the blog post emphasizes the Chrome Vulnerability Program, and specifically mentions that the victim was running a fully patched Windows 10 machine and fully patched Chrome.
>At the time of these visits, the victim systems were running fully patched and up-to-date Windows 10 and Chrome browser versions.
RCE exploits on web browsers are typically written in JS. I would also bet $$$ that if they had JS disabled, they would not have been compromised.