{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "0df46a1b70c81a60584710315adf2e2fa4f09b2d1d7dab4fb2b2f3321e629b11",
    "authored_runtime_manifest_sha256": "1be120d30de526b9f487e5d399ba0fa765de71bdb0fccaf14bba33ebd7ed21c2",
    "authored_verdict_sha256": "273e4b7ba8cd663856d9834892414d8536d1145a3506993c22b149223bcda22c",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "4f23b738-3403-4e5d-9418-d29af097addb"
  ],
  "attacker_controlled_input": "content of a page loaded in hermes's right-rail URL preview webview (attacker-selected URL), incl. a sandboxed iframe without allow-popups dispatching a synthetic ctrl+meta click with no user gesture",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "sandbox_escape",
  "claimed_surface": "viewer_document",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "sandbox_escape",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "chat open_preview tool / preview restore -> preview-pane.tsx <webview partition=persist:hermes-preview> guest -> CVE-2026-70608 OpenURL bypass -> guest did-create-window -> real BrowserWindow (no setWindowOpenHandler on the guest)",
  "validated_surface": "viewer_document"
}
