Freshly discovered bug in OpenPGP.js undermines whole point of encrypted comms

Discussion in 'other security issues & news' started by stapp, May 21, 2025.

  1. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,761
    Location:
    UK
    https://www.theregister.com/2025/05/20/openpgp_js_flaw/
     
  2. Palancar

    Palancar Registered Member

    Joined:
    Oct 26, 2011
    Posts:
    2,525
    Ouch!!! This should be a rather easy fix. GPG support and Protonmail could close this gap pretty quickly. I haven't been over there yet to hear their side of this CVE. No way they will sit on an open flaw like this without a thorough response.
     
  3. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,761
    Location:
    UK
    Please let us know when you hear anything.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.