The flaw is in a commonly used image format library and also affected Chromium browsers. Not sure why the headline and article are choosing to focus on Firefox especially.
Some are at least mentioning Chrome has the same issue: https://www.theregister.com/2023/09/12/chrome_browser_webp_exploit/
Why is this possible in browsers to begin with? We need a new generation of browsers that sandbox everything like little VMs a la QubesOS
They already do sandboxing, just sometimes things slip through the cracks and can break free of the sandbox.
yes, it was fixed with version 117.0.1
this post was submitted on 15 Sep 2023
37 points (91.1% liked)
Netsec
3 readers
1 users here now
netsec is a community-curated aggregator of technical information security content. Our mission is to extract signal from the noise — to provide value to security practitioners, students, researchers, and hackers everywhere.
Rules
- Don't do unto others what you don't want done unto you.
- No Porn, Gore, or NSFW content. Instant Ban.
- No Spamming, Trolling or Unsolicited Ads. Instant Ban.
- Stay on topic in a community. Please reach out to an admin to create a new community.
founded 2 years ago
MODERATORS