Hacker News new | ask | show | jobs
by gboone 34 days ago
From the article, a link of details:

https://infosec.exchange/@rebane2001/116606719764376414

1 comments

According to the original reporter, the bug is still exploitable and that's why the issue on the bug tracker got hidden again.

> OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS

> even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

> all from just visiting a single website once !!

> issue set to private again, hopefully it'll get fixed properly this time :p