meta_pixel
Tapesearch Logo
Log in
Security Now (Audio)

SN 1055: React's Perfect 10 - RAM Is the New Lobster

Security Now (Audio)

Leo Laporte

Cyber Crime, Malware, Technology, Encryption, Steve Gibson, Security, Hacking, Twit, Spyware, Leo Laporte

4.62.1K Ratings

🗓️ 9 December 2025

⏱️ 166 minutes

🧾️ Download transcript

Summary

A devastating new React vulnerability earned a "perfect 10" for risk, letting attackers remotely run code on a million-plus servers with a single HTTP request. Find out what happened, how fast attackers moved in, and why this bug changes everything for web security.

  • France's VanityFair face a stiff fine over cookies.
  • GrapheneOS pulls out of France over coercion worries.
  • The EU adds to the pile-on over underage social media.
  • India mandates the tracking of all smartphones.
  • Apple says no.
  • India abandons its smartphone tracking mandate.
  • India requires all encrypted messaging to be SIM-tied.
  • Scattered Lapsus$ Hunters --becomes--> SLH.
  • AI demand has driven RAM pricing sky high.
  • GRC's DNS Benchmark is finished and available.
  • Cisco may talk a good game, but they're still Cisco.
  • Browsers to ask users for local network access permission.
  • React: The worst remote code exploit in a LONG time.

Show Notes - https://www.grc.com/sn/SN-1055-Notes.pdf

Hosts: Steve Gibson and Leo Laporte

Download or subscribe to Security Now at https://twit.tv/shows/security-now.

You can submit a question to Security Now at the GRC Feedback Page.

For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.

Join Club TWiT for Ad-Free Podcasts!
Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit

Sponsors:

Transcript

Click on a timestamp to play from that location

0:00.0

It's time for security now. Steve Gibson is here with lots of security news. Apple says no. India says yes.

0:08.4

Scattered lapses hunters has a new name. Ram prices going through the roof.

0:15.0

And Steve's announcing a new product finally available for sale as of today.

0:21.7

All of that and the worst code exploit in a long time.

0:25.0

Next on Security Now.

0:31.5

Podcasts you love.

0:33.5

From people you trust.

0:36.0

This is Twitter.

0:43.9

This is Security Now with Steve Gibson.

0:49.5

Episode 155, recorded Tuesday, December 9th, 2025.

0:52.0

React's Perfect 10.

0:54.4

It's time for security now.

1:01.2

The show we cover your security, your privacy, and all the exciting attacks that are happening on the internet today with this guy right here.

1:04.7

This here is Steve Gibson, my friends.

1:06.8

Hello, Steve.

1:07.3

A comprehensive overview of bad news.

1:10.4

Well, it's one this week.

1:11.6

Holy cow.

1:13.2

Yeah.

1:13.8

There is some good news, though.

1:15.5

Oh, good.

1:16.4

The benchmark is done, and it's on sale.

...

Transcript will be available on the free plan in 17 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from Leo Laporte, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of Leo Laporte and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.