Actively exploited sandbox RCE in all Chromium versions

(nvd.nist.gov)

51 points | by negura 1 hour ago

4 comments

  • Cider9986 41 minutes ago
    Brave is beating GrapheneOS on update timeliness:

    https://github.com/GrapheneOS/Vanadium/releases

    https://github.com/brave/brave-browser/releases

    Only if you use Nightly wait maybe not.

    • anon109 16 minutes ago
      Is graphene even affected? JIT is disabled in default configurations.
    • chuckadams 29 minutes ago
      The release version just now updated to 152.0.7977.83 which has the fix.
  • Terr_ 16 minutes ago
    As somebody who prefers to browse with JS off whenever possible, there's something absurd about the balance everyone takes for granted between (A) your personal safety against a devastating hack by malicious code and (B) surveillance advertising.

    "Sorry, but to enter this shop you need to take one of the used syringes from that pile some dude delivers every day and poke yourself with it."

  • petra303 45 minutes ago
    Only a score of 8.8?
    • teravor 41 minutes ago
      RCE inside sandbox, so requires chaining with another 0day.
      • iririririr 1 minute ago
        what is online ad networks for $100, alex
      • zahlman 27 minutes ago
        What exactly does "RCE inside sandbox" describe that goes beyond "the webpage can supply arbitrary JavaScript and the JavaScript engine executes it", but is still isolated from the system?
        • jnwatson 23 minutes ago
          It means it can execute arbitrary machine code in the sandbox.
  • colincowardly 15 minutes ago
    [dead]