logoalt Hacker News

Retr0idtoday at 2:14 AM1 replyview on HN

I don't expect an unbounded scope but I do expect it to cover the big scary headline items like RCE. Additionally, this can be exploited without MitM if you combine with e.g. a DNS cache poisoning attack. And they can still fix it even if they're not willing to pay a bounty.


Replies

tptacektoday at 2:16 AM

DNS poisoning is a MITM vector; in fact, it's the most popular MITM vector.

show 1 reply