3 ms·
Yes, it says right in the CVE > allowed a remote attacker to execute arbitrary code *inside the sandbox*
by socalgal2 1mo ago
Yes, it says right in the CVE
> allowed a remote attacker to execute arbitrary code *inside the sandbox*
- mikeweiss 1mo agoSo then what's the big deal? If you had JavaScript turned off it would allow code to run in the sandbox anyway?