Apple patches eight Safari code execution flaws

By

Credential disclosure bug squashed.

Packaged with Apple's latest Mavericks operating system (version 10.9.1), are fixes for several vulnerabilities in the tech giant's Safari web browser.


Safari 7.0.1 was released on Monday by the company, and the browser update addresses eight arbitrary code execution flaws, as well as a bug that could allow users' credentials to be disclosed.

The arbitrary code execution vulnerabilities, detailed in a posting on Apple's support page, could lead to “unexpected application termination” or to malicious code being executed by an attacker if a user visits an infected website, the company revealed.

Google's Chrome security team disclosed three of the code execution flaws to Apple.

Exploit of the information disclosure bug in Safari (CVE-2013-5227) could be leveraged through websites that utilize autofill, Apple said.

“Safari may have autofilled user names and passwords into a subframe from a different domain than the main frame,” Apple said of the bug. “This issue was addressed through improved origin tracking.”

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Qantas facing 'significant' data theft after cyber attack

Qantas facing 'significant' data theft after cyber attack

Home Affairs officer accessed data on "friends and associates"

Home Affairs officer accessed data on "friends and associates"

International Criminal Court hit by cyber attack

International Criminal Court hit by cyber attack

SA Power Networks tackles IAM, cloud security under five-year strategy

SA Power Networks tackles IAM, cloud security under five-year strategy

Log In

  |  Forgot your password?