Security flaw hits Safari on Windows

Powered by SC Magazine
 

GLOBAL - Security researcher Aviv Raff claims to have found the first security vulnerability in Apple's Safari browser on Windows only hours after the software was released.

Raff tested the application against a standard browser security testing tool.

"A first glance at the debugger showed me that this memory corruption might be exploitable. Although I'll have to dig more to be sure of that," he wrote on his blog.

Apple unveiled a beta of a Windows version of its Safari web browser on Monday. The final product is scheduled for release in October.

In a keynote presentation at Apple's Worldwide Developers Conference in San Francisco, chief executive Steve Jobs claimed that the browser would run up to twice as fast as Microsoft's Internet Explorer, but did not mention Internet Explorer's security record.

Apple lists the browser's security as one of 12 reasons "why you'll love Safari" and adds that "Apple engineers designed Safari to be secure from day one ".

Raff worked on the "Month of Apple bugs" earlier this year, during which researchers published details on a slew of vulnerabilities in the software.

It was intended to challenge Apple's security record. He took the company's boasting about Safari's security as a personal challenge.

"So I've decided to take it for a test drive and ran Hamachi. I wasn't surprised to get a nice crash few minutes later," he wrote. Hamachi is a tool that tests a browser's integrity.

"Don't you hate those pathetic claims?" he said in the closing of his post in reference to Apple's marketing speak.

Apple did not immediately respond to a request for comment.

Copyright ©v3.co.uk


Security flaw hits Safari on Windows
 
 
 
Top Stories
ANZ looks to life beyond the transaction
If digital disruptors think an online payments startup could rock the big four, they’ve missed the point of why people use banks, says Patrick Maes.
 
What InfoSec can learn from the insurance industry
[Blog post] Another way data breach laws could help manage risk.
 
A ten-point plan for disrupting security
[Blog post] How can you defend the perimeter when it’s in the cloud?
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  29%
 
Application integration concerns
  3%
 
Security and compliance concerns
  27%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  21%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  4%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 1041

Vote