New ask Hacker News story: Ask HN: How serious is the WebP bug?
Ask HN: How serious is the WebP bug?
3 by skilled | 0 comments on Hacker News.
I have not seen any in-depth coverage of this so I thought I would ask HN and perhaps people with more expertise can provide clarity. For starters, the context: https://ift.tt/qiHYx42 https://ift.tt/xdy6IG9 https://ift.tt/P8Ejvtm https://ift.tt/np0rgGt —————— Google themselves said in their update that they found the vulnerability thanks to Citizen Lab, does this mean that the CVE affects and can be exploited in more than just browsers - realistically speaking. The CVE was assigned specifically to Chrome and it says “through a maliciously crafted HTML page”, but wasn’t the iOS bug specific to iMessage? That is also the part I don’t understand fully. Quite a few software/projects have pushed an update for their libwebp versions now, so that’s why I am curious.
3 by skilled | 0 comments on Hacker News.
I have not seen any in-depth coverage of this so I thought I would ask HN and perhaps people with more expertise can provide clarity. For starters, the context: https://ift.tt/qiHYx42 https://ift.tt/xdy6IG9 https://ift.tt/P8Ejvtm https://ift.tt/np0rgGt —————— Google themselves said in their update that they found the vulnerability thanks to Citizen Lab, does this mean that the CVE affects and can be exploited in more than just browsers - realistically speaking. The CVE was assigned specifically to Chrome and it says “through a maliciously crafted HTML page”, but wasn’t the iOS bug specific to iMessage? That is also the part I don’t understand fully. Quite a few software/projects have pushed an update for their libwebp versions now, so that’s why I am curious.
Comments
Post a Comment