New Mac OS X exploit disclosed

By

Auto-launch feature in Safari leaves door open for attack.

New Mac OS X exploit disclosed
Security researchers have posted exploit code for a Mac OS X vulnerability that runs through Apple's Safari web browser. 

A successful exploit could allow for remote code execution, according to the original posting of the vulnerability. Security firm Secunia gave the vulnerability its second-highest rating of 'highly critical'. 

The vulnerability was disclosed by a security researcher known only as 'LMH' as part of the Month of Apple Bugs project which aims to disclose a new Mac OS vulnerability every day in January. 

The exploit uses a default feature in Safari originally designed to streamline the download and launch of files.

By default, Safari allows for several types of files to be opened automatically, including disk image (.dmg) files which are often used to compress applications for download.

The vulnerability lies in the way Mac OS X processes disk images. A specially crafted .dmg file could cause an application crash that would leave the attacker free to execute malicious code.

The vulnerability can be mitigated by turning off the 'Open safe files after downloading' option in Safari's preference panel, according to Secunia.

'LMH' released code for a similar exploit in November which also used the 'Open safe files' feature in Safari to launch .dmg files that targeted another vulnerability in OS X. 
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:

Most Read Articles

Orica to set new workforce systems live in Australia in July

Orica to set new workforce systems live in Australia in July

Lion builds an app to detect its beers on tap in venues

Lion builds an app to detect its beers on tap in venues

ANZ Institutional readies go-live for "multi-agent chatbot" amie

ANZ Institutional readies go-live for "multi-agent chatbot" amie

Victoria Police refreshes online reporting

Victoria Police refreshes online reporting

Log In

  |  Forgot your password?