CVE-2025-43330: breaking out of a sandbox using font files
2 faxmeyourcode 1 9/17/2025, 3:08:47 PM bsssq.xyz ↗
Comments (1)
faxmeyourcode · 1h ago
I am not the author of this post. The exploration of the scheme based sandbox permissions DSL was interesting to me. It's a classic issue of a custom parser with bad input validation.