logoalt Hacker News

spaqin • yesterday at 6:36 AM • 1 reply • view on HN

Accessing any website is basically Remote Code Execution, but for some reason starting up a browser isn't a CVE.


Replies

etatester • yesterday at 7:42 AM

Good example because all that code is indeed run sandboxed, which is exactly what we need in native apps as well. "Any website" cannot access anything on my computer without explicit and often temporary permission.