hyper icon indicating copy to clipboard operation
hyper copied to clipboard

libwebp day-0 vulnerability

Open technocrat opened this issue 2 years ago • 1 comments

  • [ X] Your Hyper.app version is 3.4.1. Please verify you're using the latest Hyper.app version
  • [ X] I have searched the issues of this repo and believe that this is not a duplicate

Please see ARS Technical Report. Hyper is flagged as vulnerable by Bob Rudis' positron. I'll need to switch to another terminal pending patch (with regret!).

technocrat avatar Oct 01 '23 19:10 technocrat

Just tested the latest 4.0.0-canary.5 version using positron, the vulnerable version of electron is still there. Quite sad to stop using this app because of this :(

$ find /Applications -type f -name "*Electron Framework*" -exec ./positron "{}" \;
/Applications/Hyper.app: Chrome/108.0.5359.215 Electron/22.3.1 🔴

ayndqy avatar Oct 24 '23 23:10 ayndqy