Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

“Zero-Click RCE”

This appears to require attacker controlled data already being written to a settings XML file in specific locations on disk.

Put simply, this requires another prerequisite arbitrary file write vulnerability to be reachable.

This isn’t “zero click” unless we’re going under the assumption that an attacker already has full control over my machine before that. At best, this is a persistence mechanism, not initial access.

 help



We are living through CVE-inflation (or CVEflation?) where anyone who discovers a bug using LLMs will instantly claim it is huge security hole.

This is a third bug that emerged following a maintainer fix. If you check my profile, you might be able to reconsider your statement.

same privileges, the attacker does not have full control of the system.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: