Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

libwebp day-0 vulnerability #7506

Open
technocrat opened this issue Oct 1, 2023 · 1 comment
Open

libwebp day-0 vulnerability #7506

technocrat opened this issue Oct 1, 2023 · 1 comment

Comments

@technocrat
Copy link

  • [ X] Your Hyper.app version is 3.4.1. Please verify you're using the latest Hyper.app version
  • [ X] I have searched the issues of this repo and believe that this is not a duplicate

Please see ARS Technical Report. Hyper is flagged as vulnerable by Bob Rudis' positron. I'll need to switch to another terminal pending patch (with regret!).

@ayndqy
Copy link

ayndqy commented Oct 24, 2023

Just tested the latest 4.0.0-canary.5 version using positron, the vulnerable version of electron is still there. Quite sad to stop using this app because of this :(

$ find /Applications -type f -name "*Electron Framework*" -exec ./positron "{}" \;
/Applications/Hyper.app: Chrome/108.0.5359.215 Electron/22.3.1 🔴

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants