3 ms·
This is baseless. As per the article Google Chrome used NSS by default for years during which this vulnerability existed, so they're admitting their own product
by schmichael 5y ago
This is baseless. As per the article Google Chrome used NSS by default for years during which this vulnerability existed, so they're admitting their own product was affected. The article goes into detail about how Google's oss-fuzz project neglected to find this bug.
The author was even so kind as to boldface the first sentence here saying "the vendor did everything right":
> This wasn’t a process failure, the vendor did everything right. Mozilla has a mature, world-class security team. They pioneered bug bounties, invest in memory safety, fuzzing and test coverage.
I don't know how anyone could find a more gracious way to find and publish a vulnerability.