Skip to main content

Homeland Security Warns of Apple’s Safari Security Bug

Yes, Apple users, it is a sad truth, but you have security flaws too. The Danish security firm Secunia has discovered a vulnerability in the Safari web browser that it has labeled “highly critical”, the most serious security rating the firm can give. The flaw has been confirmed by the United States Computer Emergency Readiness Team, a Department of Homeland Security, and an advisory has been issued.

So far the bug is specifically targeting Windows operating systems, but Apple’s OS may also be affected. The flaw allows hackers to access key information when the user opens webmail services like Gmail, Hotmail, or Yahoo. The hacker can then log user data including passwords and even credit card information. The warning also claims that specially crafted websites can grant hackers access, as can closing specific pop ups.

Recommended Videos

The issue is specifically related to a badly coded section in Safari. Apple has met the security flaw with the same forthcoming attitude and tenacity that they meet all security flaws – in other words they have remained silent on the subject and refuse to comment. No patch has been released, and it is anyone’s guess when or if there will be one. Until there is, Secunia recommends that you “Do not visit untrusted web sites or follow links from untrusted sources. Do not authenticate to sites that use HTTP basic authentication and use redirections to different domains.”

The Safari browser has been plagued with security issues since its release, and Apple has faced criticism for releasing patches without announcing the security flaw that the patch is for. In March, Apple released 16 patches for Safari, including 10 that specifically affected Mac OS X.

Topics
Ryan Fleming
Former Digital Trends Contributor
Ryan Fleming is the Gaming and Cinema Editor for Digital Trends. He joined the DT staff in 2009 after spending time covering…
Update your Apple devices now to fix these dangerous exploits
A person using a laptop with a set of code seen on the display.

If you’re an Apple user -- whether you have a Mac, an iPhone, an iPad, or an Apple Watch -- you need to update your devices as soon as possible. That’s because Apple has discovered three actively exploited vulnerabilities that could cause your devices serious harm, and the patches are already out to fix them.

One of the bugs was found in Apple’s Security framework and would allow a malicious app to completely bypass a device’s signature validation. Another bug concerns the WebKit browser engine and could grant a threat actor the ability to run arbitrary code when a victim views a certain web page.

Read more
MacBooks could finally get Face ID to boost your security
Apple's 15-inch MacBook Air placed on a desk.

Apple is working on bringing its Face ID authentication system to MacBooks, in what could be a major move to boost your Mac’s security. That’s according to a newly granted patent (number 11727718) that describes the benefits of Face ID and how it could be added to Apple’s laptops.

In the patent, Apple explains that computers are capable of a great deal of different tasks, and many of them can involve storing or handing over your sensitive information -- information that should not fall into the wrong hands. To stop that from happening, some form of authentication system (like Face ID) could be implemented into laptops to toughen up their security.

Read more
In the age of ChatGPT, Macs are under malware assault
A person using a laptop with a set of code seen on the display.

It's common knowledge -- Macs are less prone to malware than their Windows counterparts. That still holds true today, but the rise of ChatGPT and other AI tools is challenging the status quo, with even the FBI warning of its far-reaching implications for cybersecurity.

That may be why software developer Macpaw launched its own cybersecurity division -- dubbed Moonlock -- specifically to fight Mac malware. We spoke to Oleg Stukalenko, Lead Product Manager at Moonlock, to find out whether Mac malware is on the rise, and if ChatGPT could give hackers a massive advantage over everyday users.
State-sponsored attacks

Read more