Serious flaw found in Safari

 

A researcher has found a flaw that would allow hackers to steal information from those using Mac OS X 10.5, aka Leopard, or Safari for the PC.

The flaw was found by open source software developer Brian Mastenbrook. It occurs when the Safari browser interacts with RSS feeds and makes the personal information of the user vulnerable.

"Safari ... is vulnerable to an attack that allows a malicious web site to read files on a user's hard drive without user intervention," Mastenbrook wrote on his blog.

"This can be used to gain access to sensitive information stored on the user's computer, such as emails, passwords, or cookies that could be used to gain access to the user's accounts on some web sites."

While he understandably does not go into detail he says that people using OS X 10.5 are vulnerable no matter what browser they are using and PC users are at risk if using the Safari browser.

He has published a suggested workaround for Apple users but advises PC users of Safari to change browser for the moment.

Mastenbrook is seen as a reliable source who has in the past found other flaws with Apple’s software.

Copyright ©v3.co.uk


Serious flaw found in Safari
 
 
 
 
 
Top Stories
Vito Forte: A CIO for tough times
Fortescue Metals CIO talks vendor management and innovation.
 
Telstra shifts BigPond email to Windows Live
All data to be migrated to Microsoft cloud.
 
Vodafone Australia churn nears half a million for 2011
British joint owners 'not pleased'.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Would you be concerned about your business' email data being hosted offshore?

   |   View results
Yes
  84%
 
No
  16%
TOTAL VOTES: 232

Vote