logoalt Hacker News

innocent_name • today at 12:15 PM • 3 replies • view on HN

Wasn't it due to poor security? libjxl had notorious bugs that would've on par with webp exploit, if present in browser:

https://security.snyk.io/vuln/?search=libjxl

I remember Project Zero cautioning Google's browser team against adding insecure decoders/encoders.


Replies

erk__ • today at 1:01 PM

No, that was not part of the reason the Google Chrome team gave: https://groups.google.com/a/chromium.org/g/blink-dev/c/WjCKc...

➕ show 1 reply
j16sdiz • today at 1:56 PM

that's what firefox said, not chrome

dncornholio • today at 12:38 PM

Probably why Google implemented their own decoder in Rust

https://developer.chrome.com/blog/jpeg-xl-in-chrome#safety_f...

➕ show 2 replies