3 ms·
True, but either way the exploit needs to be addressed. While I agree the attack vector is pretty awful, I was just curious exactly what the exploit was. The
by EMM_386 3y ago
True, but either way the exploit needs to be addressed.
While I agree the attack vector is pretty awful, I was just curious exactly what the exploit was. The article doesn't even mention it.
It links to Apple, which is likely that 0-day 0-click that Pegasus uses (BLASTPASS). They report that as a flaw in PassKit though, which would not affect Android or Windows.
That's why I was thinking the WebP overflow?
That is actually worse, and makes the discussion here even more off-topic, because that has nothing to do with JavaScript. I has to do with decoding WebP images.
https://www.tarlogic.com/blog/cve-2023-4863/ https://www.tarlogic.com/blog/cve-2023-4863/