Actively exploited sandbox RCE in all Chromium versions: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) nvd.nist.gov/vuln/detail/cve-2026-85046

So you don't even need a JS? just a crafted HTML page? Lmao. So much bloated code running and on top of that now we have an AI generated code. Security is gonna be a nightmare for most people

reshared this

in reply to nixCraft 🐧

Been working on an #AI project for work. It's been feeling like most of the documentation was generated (and not validated).

Don't get me wrong, I'll point #Gemini at my git repo and tell it to generate documentation, but I pretty much always have to heavily edit for correctness and vocabulary (so it's in my voice/style). Basically, letting AI write the initial content allows me to skip the "rough draft" step.