Hacker News new | past | comments | ask | show | jobs | submit login

It only works on mobile (not Firefox) and on Safari.

It's also easy to abuse [1]

[1]: https://blog.redteam.pl/2020/08/stealing-local-files-using-s...




This looks more like an implementation flaw than being easy to abuse. The API is still useful after it is patched.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: