Apple patches eight Safari code execution flaws

By
Follow google news

Credential disclosure bug squashed.

Packaged with Apple's latest Mavericks operating system (version 10.9.1), are fixes for several vulnerabilities in the tech giant's Safari web browser.


Safari 7.0.1 was released on Monday by the company, and the browser update addresses eight arbitrary code execution flaws, as well as a bug that could allow users' credentials to be disclosed.

The arbitrary code execution vulnerabilities, detailed in a posting on Apple's support page, could lead to “unexpected application termination” or to malicious code being executed by an attacker if a user visits an infected website, the company revealed.

Google's Chrome security team disclosed three of the code execution flaws to Apple.

Exploit of the information disclosure bug in Safari (CVE-2013-5227) could be leveraged through websites that utilize autofill, Apple said.

“Safari may have autofilled user names and passwords into a subframe from a different domain than the main frame,” Apple said of the bug. “This issue was addressed through improved origin tracking.”

This article originally appeared at scmagazineus.com

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Australia's critical infrastructure security laws "toothless"

Australia's critical infrastructure security laws "toothless"

"CanisterWorm" supply chain malware attacks npm

"CanisterWorm" supply chain malware attacks npm

Gov proposes disclosure delay for most serious cyberattacks

Gov proposes disclosure delay for most serious cyberattacks

US regulator bans imports of new foreign-made routers

US regulator bans imports of new foreign-made routers

Log In

  |  Forgot your password?