> but kernel exploits have been crafted out of scrollbars in the past.
But that would be a Chromium CVE, wouldn't it?
Zero days of course happen, but I think it's reasonable for a normal consumer to leave them out of their threat model.
But that would be a Chromium CVE, wouldn't it?
Zero days of course happen, but I think it's reasonable for a normal consumer to leave them out of their threat model.
Direct2D, DirectWrite, et al. are all technologies introduced with NT6, aka Windows Vista and 7.
Is Supermium passing webfonts directly to the Windows font renderer instead of going through Skia? A good test for this might be whether emojis render properly in Windows XP, which doesn't natively support colored fonts.
So you don't really need to fall back to GDI. Though I wouldn't say older versions of DirectX would be any more secure than GDI.