Settings

Theme

CVE-2025-43330: breaking out of a sandbox using font files

bsssq.xyz

3 points by faxmeyourcode 3 months ago · 3 comments

Reader

faxmeyourcodeOP 3 months ago

I am not the author of this post. The exploration of the scheme based sandbox permissions DSL was interesting to me. It's a classic issue of a custom parser with bad input validation.

  • bsssq 3 months ago

    thanks for sharing! yes, it's a textbook vulnerability that was really quite trivial to exploit.

    • faxmeyourcodeOP 3 months ago

      It was a fun read - digestible for those of us without a ton of experience in advanced security background knowledge.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection