Conversation

twitter.com/EtTuCarl/statu It's 3 vulnerabilities in Skia, which is a 2D rendering library used by Android, Firefox and Chromium. It's widely used and the context where an attacker could gain code exec varies. For Chromium on Android it's in the Chrome or WebView renderer sandbox.
Quote Tweet
@DanielMicay Do you know exactly what part of Android does this (specific to built-in photo app, webview, or something else)? twitter.com/cybersecboardr…
2
6
Replying to and
It's part of what Mozilla's Servo project has the potential to replace, similarly to how it replaced the Firefox CSS engine with one written in Rust (Stylo). Those components handle a very complex problem and consume untrusted input so memory unsafe languages are a big liability.
1
1
Show replies
Show replies