4 ms·
Even on a Linux desktop OS with a single user, it's still a security risk as it skips over a last line of defence. If a Chrome bug is found that allows web pag
by PlutoIsAPlanet 3y ago
Even on a Linux desktop OS with a single user, it's still a security risk as it skips over a last line of defence.
If a Chrome bug is found that allows web pages to arbitrary code execution, it can be chained with an exploit like this to infect more than just the user account, potentially, depending on the computer, the firmware itself.
- IshKebab 3y agoSure but most malware doesn't really care about infecting more than the user. The only reason to infect firmware is to gain persistence in the face of OS reinstalls, but those are very rare in general. Only targeted NSA level malware is going to bother with that. For normal botnet/cryptocurrency stealing malware once it has user access it has everything it needs.
- Manouchehri 3y agoIf you're able to throw a 0day at a target, there's nothing stopping you from throwing it again after they reinstall.