Discord Patched A Critical Issue In The Desktop Version Of The Messaging App Cybers Guards
Several months ago, bug bounty hunter Masato Kinugawa created an exploit chain leading to RCE and published a weekend blog post explaining the technical specifics of the process, which incorporates several bugs. Electron, the development system used for the Discord desktop client, discovered the first security problem. The JavaScript framework used by Electron — an open source initiative to build cross-platform applications capable of harnessing JavaScript, Markup, and CSS — was saved locally because the web software is not open source, and could be removed and analysed....