Open Bug 1658906 Opened 4 years ago Updated 2 years ago

Perform AVIF decoding outside the content process.

Categories

(Core :: Graphics: ImageLib, defect, P3)

defect

Tracking

()

People

(Reporter: jya, Unassigned)

References

(Blocks 1 open bug)

Details

The AVIF decoder runs the Dav1d decoder directly in content process.

Dav1d should run in the RDD, sandboxed.

Blocks: AVIF
Severity: -- → N/A
Type: defect → enhancement

I don't believe this is an enhancement.

It's a defect, AV1 decoder should never be run in the content process.

Type: enhancement → defect
Priority: -- → P3
Severity: N/A → S3
Flags: needinfo?(aosmond)

I think jbauman will have this covered.

Flags: needinfo?(aosmond)

Indeed

Assignee: nobody → jbauman
Status: NEW → ASSIGNED

Should this be labeled "sec-want"?

I don't think so. The security team has reviewed this and has determined the current situation acceptable.

Assignee: jbauman → nobody
Status: ASSIGNED → NEW
You need to log in before you can comment on or make changes to this bug.