A vulnerability in Electron applications allows attackers to bypass code integrity checks by tampering with V8 heap snapshot files, enabling local backdoors in applications like Signal, 1Password, and Slack.

  • empireOfLove2@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    12
    ·
    11 days ago

    You mean to tell me wrapping every single app in a glorified web browser container might introduce vulnerabilities you can’t control in the container???