Hacker News new | past | comments | ask | show | jobs | submit login

Are such exploits possible in electron, or is it sandboxed to prevent such errors?



The article goes into that. The RCE video at the bottom shows the entire attack chain from embed to opening calc.exe.


It is. If you turn it on. And they didn’t. Amateur hour.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: