CVE-2025-47934 - Spoofing OpenPGP.js signature verification https://lobste.rs/s/uafcpg #cryptography #security
https://codeanlabs.com/blog/research/cve-2025-47934-spoofing-openpgp-js-signatures/
If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/lobsters/statuses/114659997484826815 on your instance and quote it. (Note that quoting is not supported in Mastodon.)