tl;dr Tested versions: Google Web Designer 16.3.0.0407 (released April 2025) After my recent discovery of two client-side remote code execution vulnerabilities in Google Web Designer (previously disclosed in my articles earlier this year: CVE-2025-1079 , CVE-2025-4613 ), in April 2025 I've found yet another serious issue in the app. Versions prior to 16.4.0.0711 (released July 29, 2025) had…
tl;dr Tested versions: Google Web Designer 16.1.0.0530 (released cca. June 2024) and 16.2.0.0128 (released February 28, 2025) This issue is tracked as CVE-2025-4613 , and has been fixed in version 16.3.0.0407 , released cca. April 19, 2025. Shortly after finding my first RCE on the app , in February 2025 I’ve discovered a vulnerability in Google Web Designer that exposed its users to another…
tl;dr Tested version: Google Web Designer 16.1.0.0530 (released cca. June 2024) This issue is tracked as CVE-2025-1079 , and has been fixed in version 16.2.0.0128 , released February 28, 2025 . In November 2024 I’ve discovered a vulnerability in Google Web Designer that exposed its users on macOS and Linux to the possibility of client-side remote code execution via improper symbolic link…
tl;dr When the stars stylesheets align just right, it’s possible to escalate a harmless content injection issue to a marginally less harmless one by using certain Unicode characters to stand in for pixels in a QR code. (For fun, not profit.) Read on for details. In this article I’ll be showing you how I was able to render arbitrary QR codes in a web app that was not at all designed to do that,…