RSS Bot@lemmy.bestiver.seMB to Hacker News@lemmy.bestiver.seEnglish · 25 days agoAdult sites are stashing exploit code inside racy .svg filesarstechnica.comexternal-linkmessage-square4linkfedilinkarrow-up118arrow-down10file-textcross-posted to: privacy@programming.devprivacy@lemmy.dbzer0.compulse_of_truth@infosec.pub
arrow-up118arrow-down1external-linkAdult sites are stashing exploit code inside racy .svg filesarstechnica.comRSS Bot@lemmy.bestiver.seMB to Hacker News@lemmy.bestiver.seEnglish · 25 days agomessage-square4linkfedilinkfile-textcross-posted to: privacy@programming.devprivacy@lemmy.dbzer0.compulse_of_truth@infosec.pub
minus-squareskisnow@lemmy.calinkfedilinkEnglisharrow-up9·25 days agoThe site doesn’t really explain quite why modern browsers still happily execute javascript from inside an .svg file? It seems like a trivial thing to patch.
The site doesn’t really explain quite why modern browsers still happily execute javascript from inside an .svg file? It seems like a trivial thing to patch.