logoalt Hacker News

rcxdudetoday at 11:34 AM0 repliesview on HN

This is a little bit 'if you can execute code as a user you can execute code as a user'. All of the exploit pathways involve capabilities that would give you any number of paths to code execution. The check should probably be fixed but I question whether it's really doing much in the first place.