Chrome was updated September 11
Matrix Element Desktop updated September 15, without a changelog or advisory. (The Element update on September 13 did not include the updated electron with the fix; today’s update does, according to their announcement on Matrix.)
Many/most electron apps don’t receive timely security updates, so if you don’t want arbitrary images to be able to get code execution you might want to stop using them.
You must log in or # to comment.
Guess it’s time to finally retire Bromite
I keep hearing “exploited in the wild”, but does anyone have anything concrete on it — like, IoCs, PoC, victims … anything?