Package: chromium
Version: 56.0.2924.76-1~deb8u1

Chromium's .deb install a suid root binary
(/usr/lib/chromium/chrome-sandbox), potentially exposing the user's
system to hostile javascripts downloaded from the untrusted web.

This has already been exploited in the past:

https://bugs.chromium.org/p/chromium/issues/detail?id=76542

Debian packages should not expose users' systems to these kinds of risks
without informed consent.

Alain

Reply via email to