Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: Swordmaker
Do you know what a "Sandbox" means? The most the vulnerability can do is CRASH Safari.

Yes, I am a professional software developer, and I know what a "Sandbox" is. And I know the code it the typical browser is so complicated that its impossible to know exactly what it does, especially since they accept "broken HTML" by choice.

That's why Safari's sandbox has been bypassed before, as in the case with this vulnerability (Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism ...).

And don't think I am taking this out on Macs, because I just happen to own a few, and my primary dev box is a MacBook Pro with Yosemite.

My point is, running remote code in a browser is dangerous, period.

22 posted on 02/03/2015 5:24:02 PM PST by SecondAmendment (Restoring our Republic at 9.8357x10^8 FPS)
[ Post Reply | Private Reply | To 21 | View Replies ]


To: SecondAmendment
That's why Safari's sandbox has been bypassed before, as in the case with this vulnerability (Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism ...).

And Safari is Version 8.0.3

23 posted on 02/03/2015 5:46:14 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 22 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson