Hacker News new | ask | show | jobs
by seritools 121 days ago
You are mistaken:

> The malicious code would execute in the security context of the user who opened the Markdown file, giving the attacker the same permissions as that user.