Got a tip for us? Share it...

Security Vulnerability Found in Safari RSS

Open source programmer Brian Mastenbrook has discovered a security flaw in the way that Safari handles RSS feeds. The vulnerability, which affects both Mac and Windows versions of Safari, could allow a malicious website to gain access to sensitive user data.

I have discovered that Apple's Safari browser is vulnerable to an attack that allows a malicious web site to read files on a user's hard drive without user intervention. This can be used to gain access to sensitive information stored on the user's computer, such as emails, passwords, or cookies that could be used to gain access to the user's accounts on some web sites. The vulnerability has been acknowledged by Apple.

Mastenbrook reports that all OS X 10.5 Leopard users, regardless of whether they use Safari or RSS feeds, should protect themselves by choosing an application other than Safari for reading RSS feeds, an option available in the "RSS" tab of Safari's Preferences. Safari for Windows users should utilize a different browser until Apple issues a patch. Mastenbrook, who has received credit from Apple for reporting a number of security issues over the past year, says that Apple has not given a timeframe for a fix.

Top Rated Comments

(View all)

40 months ago
Here's my opinion: We'll be getting a Safari update soon! Yay!
Rating: 0 Positives / 0 Negatives
40 months ago
Good thing I don't use Safari to handle my RSS feeds.
Rating: 0 Positives / 0 Negatives
40 months ago
The temp fix is very easy. Everyone should do so now:


Open Safari and select Preferences... from the Safari menu.
Choose the RSS tab from the top of the Preferences window.
Click on the Default RSS reader pop-up and select an application other than Safari.

Rating: 0 Positives / 0 Negatives
40 months ago
Scary. Its amazing what people can do today. Everything was so simple before the internet :P
Rating: 0 Positives / 0 Negatives
40 months ago
I hope people start realizing that Safari isn't, as apple puts it, "the world's best browser".......
Rating: 0 Positives / 0 Negatives
40 months ago
So ... who makes the best RSS reader?
Rating: 0 Positives / 0 Negatives
40 months ago
If this doesn't affect Mail, you can switch to that as your RSS reader. I've been using Mail as my RSS reader since Leopard came out. Works better than Safari did.
Rating: 0 Positives / 0 Negatives
40 months ago

So ... who makes the best RSS reader?


google?
Rating: 0 Positives / 0 Negatives
40 months ago
I don't use RSS, but for those who do this looks like something serious as they can access your hardrive just like that. Remember this is for both Windows and Mac safari users :(:apple:
Rating: 0 Positives / 0 Negatives

[ Read All Comments ]