logoalt Hacker News

crazygringoyesterday at 9:32 PM1 replyview on HN

In this particular case, injecting content into the image to make someone read a false message doesn't seem possible. The pixel <img> tag has width and height set to one. This overrides whatever the image size is. No altered message will be readable.


Replies

matthewmacleodyesterday at 9:58 PM

This is true up until the point that someone finds a security issue with an image parser that’s present in a browser engine, and suddenly you have an RCE.

show 2 replies