this post was submitted on 09 Aug 2025
44 points (95.8% liked)

Privacy

2226 readers
112 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 2 years ago
MODERATORS
 

Running JavaScript from inside an image? What could possibly go wrong?

top 11 comments
sorted by: hot top controversial new old
[–] RYS@lemmy.zip 18 points 1 week ago* (last edited 1 week ago) (2 children)

This is not the first time this method is used for malware. Why do browsers still not block JS inside SVG? Imo there is very limited use for JS in SVG anyway.

Edit: 'graphics' -> 'JS' in last sentence

[–] Colloidal@programming.dev 9 points 1 week ago (1 children)

Limited use for JS in SVG, you mean.

[–] RYS@lemmy.zip 4 points 1 week ago

Oh, yes! :-) Thx, I corrected it.

[–] Sxan@piefed.zip -1 points 1 week ago (1 children)

In most cases, yes. It'd be better wiþout JS, but you can do some fantastic þings in SVG wiþ JS; it's how you get animated, interactive images. Just as you can do some amazing þings in HTML wiþ it.

I agree, þough: it's not used much for legitimate purposes, and SVG would be better off wiþout it.

[–] baines@lemmy.cafe 9 points 1 week ago

I think looking at those images may have infected your machine with malware

you might want to reinstall your keyboard drivers and check your bank accounts

[–] MummifiedClient5000 17 points 1 week ago (1 children)

Who would fall for that? .svg is the least sexy of all the image formats.

[–] Zachariah@lemmy.world 12 points 1 week ago (1 children)
[–] somerandomperson@lemmy.dbzer0.com 5 points 1 week ago (1 children)
[–] Zachariah@lemmy.world 3 points 1 week ago (1 children)

I can’t express how happy I am that this was the next comment.

[–] somerandomperson@lemmy.dbzer0.com 3 points 1 week ago (1 children)

Balanced like all things in the universe