Actively exploited sandbox RCE in all Chromium versions

(nvd.nist.gov)

57 points | by negura 1 hour ago

4 comments

  • Cider9986 52 minutes ago
    Brave is beating GrapheneOS on update timeliness:

    https://github.com/GrapheneOS/Vanadium/releases

    https://github.com/brave/brave-browser/releases

    Only if you use Nightly wait maybe not.

    • d2kx 10 minutes ago
      This issue is already fixed in Google Chrome (152.0.7977.83)
    • anon109 28 minutes ago
      Is graphene even affected? JIT is disabled in default configurations.
    • chuckadams 40 minutes ago
      The release version just now updated to 152.0.7977.83 which has the fix.
  • Terr_ 28 minutes ago
    As somebody who prefers to browse with JS off whenever possible, there's something absurd about the balance everyone takes for granted between (A) your personal safety against a devastating hack by malicious code and (B) surveillance advertising.

    "Sorry, but to enter this shop you need to take one of the used syringes from that pile some dude delivers every day and poke yourself with it."

  • petra303 56 minutes ago
    Only a score of 8.8?
    • teravor 53 minutes ago
      RCE inside sandbox, so requires chaining with another 0day.
      • zahlman 38 minutes ago
        What exactly does "RCE inside sandbox" describe that goes beyond "the webpage can supply arbitrary JavaScript and the JavaScript engine executes it", but is still isolated from the system?
      • iririririr 13 minutes ago
        what is online ad networks for $100, alex
  • colincowardly 26 minutes ago
    [dead]