logoalt Hacker News

procaryoteyesterday at 9:35 PM1 replyview on HN

Markdown is readable as plain text, that's kind of the point of it

There's also a pretty large jump between "I can ask the system to open this link in the default browser" and "I have built my own link handling in a memory-unsafe language to support some really fringe features, and oops it's exploitable"


Replies

NetMageSCWtoday at 12:26 AM

Except memory-unsafe and fringe features have nothing to do with this CVE, which seems incredibly dumb on the face of it.

Replace Notepad with Chrome or Edge - clicking on a link downloads content from the Internet! Oh noes!