• lurch (he/him)@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    18
    ·
    2 天前

    Headline seems intentionally vague. The updater was vulnerable to a download man-in-the-middle attack, because it used a weak certificate.

    • smeg@infosec.pub
      link
      fedilink
      English
      arrow-up
      12
      ·
      2 天前

      Which requires a malicious network operator or some other kind of DNS poisoning. Not exactly a radical exploit