| We have officially reached the logical conclusion of the feature-bloat-to-vulnerability pipeline. For nearly thirty years, notepad.exe was the gold standard for a "dumb" utility which was a simple, win32-backed buffer for strings that did exactly one thing...display text. An 8.8 CVSS on a utility meant for viewing data is a fundamental failure of the principle of least privilege. At some point, they need to stop asking "can we add this feature?" and start asking "does this text editor need a network-aware rendering stack?" |
They didn’t stop there. They also asked “does this need AI?” and came up with the wrong answer.