Hacker News new | ask | show | jobs
by 0x0 5089 days ago
> The claim you could inject arbitrary code from JS into your memory and make it executable from user space (not talking of the cross platform issue (BSD,linux, windows, MACOSX) would just be the end of JS.

> How can you even accept the claim that it can be doable.

Isn't exactly this how most/all heap spray js exploits work?

I wouldn't be so quick to dismiss the concept of this bug, even though the "poc" presented here is bogus.