Ask me anything!

Have a question you always wanted to ask Moonchild but never did? Now's your chance!
From 2026-03-08 to 2026-03-15 I'll be open to any question by the community, after which I'll provide answers.

Go here to participate: https://forum.palemoon.org/viewtopic.php?f=66&t=33222

TheRegister - Security hole that can crash any chromium-based browser

Off-topic discussion/chat/argue area with special rules of engagement.
Forum rules
The Off-Topic area is a general community discussion and chat area with special rules of engagement.

Enter, read and post at your own risk. You have been warned!
While our staff will try to guide the herd into sensible directions, this board is a mostly unrestricted zone where almost anything can be discussed, including matters not directly related to the project, technology or similar adjacent topics.

We do, however, require that you:
  • Do not post anything pornographic.
  • Do not post hate speech in the traditional sense of the term.
  • Do not post content that is illegal (including links to protected software, cracks, etc.)
  • Do not post commercial advertisements, SEO links or SPAM posts.
We also ask that you keep strongly polarizing topics like politics and religion to a minimum. This forum is not the right place to discuss such things.
Please do exercise some common sense. How you act here will inevitably influence how you are treated elsewhere.
User avatar
andyprough
Board Warrior
Board Warrior
Posts: 1300
Joined: 2020-05-31, 04:33

Re: TheRegister - Security hole that can crash any chromium-based browser

Post by andyprough » 2025-11-01, 19:45

Could be a Windows thing. I frequently use antiX where SeaMonkey is the default installed browser that you have to use to download a few other things, and its rendering has been poor and speed has been completely unremarkable for me. I've used the latest version and got rid of it as quickly as I could.

User avatar
frostknight
Keeps coming back
Keeps coming back
Posts: 918
Joined: 2022-08-10, 02:25

Re: TheRegister - Security hole that can crash any chromium-based browser

Post by frostknight » 2025-11-01, 22:16

Moonchild wrote:
2025-11-01, 14:47
I don't see that happening in this universe so it'll most likely be shrug and yawn and more ads in everyone's pocket.
I think its more likely you will displace firefox usership then become richer than those two men. Especially since at least one of them does a lot of data collection to make his fortune. An evil method of making money ie.
Although sadly an effective one as well.
I could see that happening if mozilla keeps effing up and more developers came to help you.

This doesn't sound impossible.

Although, how bad would mozilla have to eff up?

Idk....

;)
Freedom is never more than one generation away from extinction. Feelings are not facts
If you wish to be humbled, try to exalt yourself long term If you wish to be exalted, try to humble yourself long term
Favourite operating systems: Hyperbola Devuan OpenBSD
Say NO to Fascism and Corporatism as much as possible!
Also, Peace Be With us All!

User avatar
UCyborg
Keeps coming back
Keeps coming back
Posts: 772
Joined: 2019-01-10, 09:37
Location: Slovenia

Re: TheRegister - Security hole that can crash any chromium-based browser

Post by UCyborg » 2025-11-02, 09:48

Although, if the slowest way is the most correct, it may be the sanest choice, despite suffering the sluggishness. I see Pale Moon handles this attack exceptionally well, both Firefox and Chromium run PC out of RAM and page file starts to grow uncontrollably and the offending tab is difficult or impossible to close.

Edit: The responsiveness of PM is considerably worse with uBO enabled. But, what could the reason be? The exploit doesn't make network requests.

User avatar
jobbautista9
Board Warrior
Board Warrior
Posts: 1149
Joined: 2020-11-03, 06:47
Location: Philippines

Re: TheRegister - Security hole that can crash any chromium-based browser

Post by jobbautista9 » 2025-11-02, 14:25

UCyborg wrote:
2025-11-02, 09:48
The responsiveness of PM is considerably worse with uBO enabled. But, what could the reason be? The exploit doesn't make network requests.
Could probably be due to uBlock observing DOM mutations?
Image

Tired of creating stuff!

Avatar artwork by Shinki669: https://www.pixiv.net/artworks/113645617

XUL add-ons developer. You can find a list of add-ons I manage at http://rw.rs/~job/software.html.