3 ms·
Isn't this exactly why there is a sandbox? What can the RCE actually do or obtain within the sandbox?
by mikeweiss 27d ago
Isn't this exactly why there is a sandbox? What can the RCE actually do or obtain within the sandbox?
- deleted 27d ago[deleted]
- socalgal2 27d agoYes, it says right in the CVE > allowed a remote attacker to execute arbitrary code *inside the sandbox*
- mikeweiss 27d agoSo then what's the big deal? If you had JavaScript turned off it would allow code to run in the sandbox anyway?
- nikanj 27d agoDoesn’t any <script> tag let you run arbitrary code inside a sandbox anyway?
- lima 26d agoInside the JS sandbox, not the browser's outer containment sandbox.