Text Injection But Make It Spicy: Rendering QR Codes With Unicode Block Characters
Related
More from Bálint Magyar
tl;dr Tested versions: Google Web Designer 16.3.0.0407 (released April 2025) After my recent discovery of two client-side remote code execution vulnerabilities in Google Web Designer (previously disclosed in my articles earlier this year: CVE-2025-1079, CVE-2025-4613), in April 2025 I've found yet another serious issue in the app....
tl;dr Tested versions: Google Web Designer 16.1.0.0530 (released cca. June 2024) and 16.3.0.0407 (released February 28, 2025) This issue is tracked as CVE-2025-4613, and has been fixed in version 16.3.0.0407, released cca. April 19, 2025. Shortly after finding my first RCE on the app, in February 2025 I’ve discovered a vulnerability...
tl;dr Tested version: Google Web Designer 16.1.0.0530 (released cca. June 2024) This issue is tracked as CVE-2025-1079, and has been fixed in version 16.2.0.0128, released February 28, 2025. In November 2024 I’ve discovered a vulnerability in Google Web Designer that exposed its users on macOS and Linux to the possibility of client-side...
tl;dr When the stars stylesheets align just right, it’s possible to escalate a harmless content injection issue to a marginally less harmless one by using certain Unicode characters to stand in for pixels in a QR code. (For fun, not profit.) Read on for details. In this article I’ll be showing you how I was able to...