Hacker News new | past | comments | ask | show | jobs | submit login

The biggest issue here is that this image parsing was done by such a high-privileged process. What happened to all the sandboxes and stuff?



From the original article [0], last line: "In a future post (currently being finished), we'll take a look at exactly how they escape the IMTranscoderAgent sandbox."

[0]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...


Is the CoreGraphics ImageIO stuff privileged?




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: