Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

CVE-2019-11708: sandbox escape using Prompt:Open

Reporter Coinbase Security

Impact high

Description Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer.

References Bug 1559858



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: