CVE-2025-43330: breaking out of a sandbox using font files (bsssq.xyz) 3 points by faxmeyourcode 12mo ago ↗ HN
[–] faxmeyourcode 12mo ago ↗ I am not the author of this post. The exploration of the scheme based sandbox permissions DSL was interesting to me. It's a classic issue of a custom parser with bad input validation.
1 comment of 3
[ 3.1 ms ] story [ 14.1 ms ] thread