3 ms·
Sibling comments address this pretty well, but the ideas I mentioned still seem like good ideas for a few reasons: - The article mentions the sample exploit is
by Jap2-0 4y ago
Sibling comments address this pretty well, but the ideas I mentioned still seem like good ideas for a few reasons:
- The article mentions the sample exploit is based on the test case
- The point of obfuscation isn't to prevent exploitation, it's to delay it
- A sibling mentions the delay between patch and release as an issue; because of the only ~1 day delay here it seems like this was intentionally merged right before release, so buying even a day (or two or three, to account for time to update) would be enough to mitigate most of the impact
There's a big difference between reading a snippet of JS and understanding the inner workings of a JIT, especially under time pressure.