Skip to content

Comment on Adult sites are stashing exploit code inside svg files

Comments

I'm shocked this attack works. I thought the last 15 years of browser dev were largely isolating domains from each other to prevent cross-site attacks, and introducing consent flows for little used and/or dangerous platform features.

Running JS inside an image format sounds like a thing they could add permissions for (or a click-to-play overlay), especially if it can talk to other sites.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.