How one Twitch chat message became code execution on a streamer’s PC
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
How one Twitch chat message became code execution on a streamer’s PC
Unofficial Hacker News client; not affiliated with Y Combinator.
superkuh · · focus · HN ↗
This is not a bug. This is the the entire design architecture's intent for modern JS application execution based "web". If this was the correct choice for the web then this should not be a problem at all. But we all know it is. The architecture choice forces this. Until we stop arbitrarily executing random third party code this will always happen. And the consequences will get worse and worse as more bare metal features are exposed in to browsers JS virtual machines.
Be the change in the world you want to see. Turn javascript off. Use real native applications that cannot change underneath you.
winstonwinston · · focus · HN ↗
But they can change (underneath). Native app is one bug away from arbitrary code execution. When remote content triggers this bug, it becomes RCE. In this case it was javascript engine bug, in any other it could be your photo viewer or whatever native code you are running with untrusted content. The untrusted content being an image you are viewing.