logoalt Hacker News

matthewmacleodyesterday at 9:58 PM2 repliesview on HN

This is true up until the point that someone finds a security issue with an image parser that’s present in a browser engine, and suddenly you have an RCE.


Replies

crazygringotoday at 1:29 AM

If you have access to an exploit and want to compromise someone with an image, you'd usually just send it to them directly via e-mail or SMS or AirDrop or whatever, or all of the above. And it'll even work if your image is linked in an email via HTTPS.

Trying to MITM an existing tracker pixel when they're connected to public WiFi sounds like practically the hardest way to do it.

show 1 reply