top | item 22342352

(no title)

kingkilr | 6 years ago

(Former Firefox Security Engineer)

I suspect it's because Firefox exploits have looked the same for the last several years -- there has not been a lot of novelty required to implement an exploit, given an arbitrary read/write primitive.

P0 does report vulnerabilities to Firefox though, and they obviously get fixed, they're just not particularly interesting to exploit.

discuss

order

saagarjha|6 years ago

> I suspect it's because Firefox exploits have looked the same for the last several years -- there has not been a lot of novelty required to implement an exploit, given an arbitrary read/write primitive.

Surely other browsers do not differ from this significantly?

tedunangst|6 years ago

An arbitrary write primitive in the chrome render process hasn't been game over for quite some time.

arkadiyt|6 years ago

Perhaps that'll change once Project Fission lands in the stable release