2026-04-23 18:31 UTC
Replies (2)
-
@MangoCats@feddit.it 2026-04-23 19:05
>most of the results are technically correct, but, within the context of the project, not something anyone’s going to take the time to fix. I don't mind leaving "technically correct" vulnerabilities in place while there's no known way to create an exploit. If you've got a vuln with a known exploit and are relying on "but nobody is ever going to actually try that on us" - then you're part of the problem, a big part.
-
@jj4211@lemmy.world 2026-04-24 12:11
Note that in this case, very specifically, they had to yank Firefox's javascript engine out of Firefox "but without the browser’s process sandbox and other defense-in-depth mitigations.” They had to remove the mechanisms designed to quash vulnerabilities. And they had to test explicitly against Firefox 147 vintage because Firefox 148 had already fixed the two issues that Mythos exploited to get an impressive number. Before Mythos even ran the key problems had been found and patched...