EN Security researchers disclosed a remote code execution flaw that breaks out of Chromium's sandbox and is already being exploited in the wild, affecting Chrome, Edge, Brave, and every other Chromium-based browser.
KO 크로미움 기반 브라우저(크롬·엣지·브레이브 등) 전체에 영향을 주는 원격코드실행(RCE) 취약점이 공개됐다. 이미 실제 공격에 악용되고 있는 것으로 확인됐다.
EN Sandbox escapes are the scariest class of browser bug because they turn 'just visiting a page' into full system compromise — expect an emergency patch within days, and the real story is how long attackers had this before disclosure.
KO 샌드박스 탈출은 '페이지만 열어도' 시스템 전체가 뚫릴 수 있는 최악의 취약점 유형이다. 며칠 내 긴급 패치가 나올 가능성이 크고, 진짜 문제는 공개 전까지 공격자들이 이걸 얼마나 오래 써먹었는지다.
- sandbox escape — 브라우저 격리 환경을 벗어나 시스템 권한을 얻는 것
- actively exploited — 실제로 공격에 악용되고 있는 (이론상 취약점이 아닌)
- in the wild — 실제 환경에서, 통제된 실험실이 아닌