3 ms·
There is a lot of talk here but no real answers. What exploit is this using to infect Windows computers and Android phones? Does this have to do with the 0-d
by EMM_386 3y ago
There is a lot of talk here but no real answers. What exploit is this using to infect Windows computers and Android phones?
Does this have to do with the 0-day exploit in WebP that is causing a huge mess for the entire ecosystem?
Everyone seems to be fixated on "ads shouldn't be able to run JavaScript" and the like.
What exactly is that JavaScript in the ad taking advantage of? Why would it matter that it's an ad and not just a website?
If ads can do it, web pages can do it.
- chucksmash 3y agoYou select the web pages, but the ads select you.
- EMM_386 3y agoTrue, but either way the exploit needs to be addressed. While I agree the attack vector is pretty awful, I was just curious exactly what the exploit was. The article doesn't even mention it. It links to Apple, which is likely that 0-day 0-click that Pegasus uses (BLASTPASS). They report that as a flaw in PassKit though, which would not affect Android or Windows. That's why I was thinking the WebP overflow? That is actually worse, and makes the discussion here even more off-topic, because that has nothing to do with JavaScript. I has to do with decoding WebP images. https://www.tarlogic.com/blog/cve-2023-4863/ https://www.tarlogic.com/blog/cve-2023-4863/