this post was submitted on 10 Oct 2023
832 points (97.0% liked)

Programmer Humor

32479 readers
315 users here now

Post funny things about programming here! (Or just rant about your favourite programming language.)

Rules:

founded 5 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 93 points 1 year ago (11 children)

*Badly outdated Chrome with a bunch of critical vulnerabilities.

Don't forget every Electron app comes with its own Chrome.

[–] [email protected] 43 points 1 year ago* (last edited 1 year ago) (8 children)

Last time I checked the version Electron used by Discord was severely out of date causing several issues that had been solved months ago upstream. That’s the fault of Discord, not Electron but there are several issues with Chromium that I have to deal with on every Electron app I use. Compose sequences are still partially broken. I reported it at Chromium but they responded with a video of them testing it on Windows (not with a VM), said they couldn’t reproduce the issue (with a Linux specific input method?!) and then marked it as unreproducible.

[–] [email protected] 23 points 1 year ago (3 children)

Wait, you're telling me that Discord is probably still vulnerable to the Webp RCE vulnerability?

[–] [email protected] 19 points 1 year ago

They use plain text and there biggest shareholder is the Tencent (the CCP let's be real) are you surprised? It's literally a data farm for China...

[–] [email protected] 7 points 1 year ago

They updated to a version that included a patch for that exploit, however it doesn't matter in the grand scheme of things, because they're still on 22.x, support for which has already been terminated

[–] [email protected] 7 points 1 year ago

They probably manually added the patch.

load more comments (4 replies)
load more comments (6 replies)