logoalt Hacker News

spaqin • today at 6:36 AM • 1 reply • view on HN

Accessing any website is basically Remote Code Execution, but for some reason starting up a browser isn't a CVE.


Replies

etatester • today at 7:42 AM

Good example because all that code is indeed run sandboxed, which is exactly what we need in native apps as well. "Any website" cannot access anything on my computer without explicit and often temporary permission.