Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Brave is beating GrapheneOS on update timeliness:

https://github.com/GrapheneOS/Vanadium/releases

https://github.com/brave/brave-browser/releases

Only if you use Nightly wait maybe not.

 help



Is graphene even affected? JIT is disabled in default configurations.

That's how the system or browser should be configured. Secure by default and any insecurity must be an opt-in. But Google won't do it because their websites are JS heavy monster trucks and millions of websites run their tracking scripts which require JIT enabled by default for optimal page load.

This issue is already fixed in Google Chrome (152.0.7977.83)

TFA says

> Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.

So it was fixed in 152.0.7977.82 (before .83), if I read that right.


You read that right. From the article:

"Affected products: ... Up to (excluding) 152.0.7977.82"

.82 is fixed.


The release version just now updated to 152.0.7977.83 which has the fix.

I upgraded Vivaldi, which is reporting 152.0.7977.112



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: