A few people have been asking about a post that was published yesterday by a security researcher who helped us fix a bug in March. Here is some additional background information:
On March 10th, we received notification that, in some cases, our HTML sanitizer was not removing onclick event handlers on buttons that could be included in blog posts. The dev team looked at the issue, repaired it and deployed a fix to our servers within 24 hours. This was a server bug, so as soon as we deployed the fix to the server, all the apps and the web client were repaired – no user action required.
We are not aware of any user being affected by the issue. Note: articles are loaded in a webview sandbox, so there is not much any malicious code could have actually done – besides redirecting you to another site or changing some of your feedly preferences.
We are lucky to have security researchers within the feedly community. As such, from time to time we receive bug reports at firstname.lastname@example.org. Our policy is to fix these bugs (even the harmless ones) within 24 hours whenever possible. As part of this process, we offer the person who reported the bug a lifetime feedly Pro account.
The process worked well in this case and we are very thankful to Jeremy for helping make feedly safer.
Happy, safe reading.