• lurch (he/him)@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    17
    ·
    1 day ago

    Headline seems intentionally vague. The updater was vulnerable to a download man-in-the-middle attack, because it used a weak certificate.

    • smeg
      link
      fedilink
      English
      arrow-up
      11
      ·
      1 day ago

      Which requires a malicious network operator or some other kind of DNS poisoning. Not exactly a radical exploit