I'm sorry, I thought I'd included the link but clearly I forgot! https://github.blog/security/vulner...ect-transition-to-rce-in-the-chrome-renderer/Curious to know more about this exploit, particularly if it's now seen actively in the wild.
I don't know that this exploit has been found in use in the wild, but there's a public proof of concept available.
An attacker would still need to get past the OS X sandbox. I assume the sandbox on Mavericks (and similar versions) has known vulnerabilities, but I have not actually checked whether this is the case. Regardless, an attacker would need to actually be targeting the sandbox on your OS, and obviously there aren't that many Chromium Legacy users out there, so it probably wouldn't be worth it. Still, I think it's better to turn off V8 optimizations.
Last edited: