Got a tip for us? Share it...

Apple Releases Safari 4.0.2

Apple today released Safari 4.0.2, now available on Apple's Safari download page or through Software Update. According to the support document associated with the release, the update addresses two security vulnerabilities that could be exploited by maliciously crafted websites. The update also reportedly improves the stability of the Nitro JavaScript engine used by Safari.

The first vulnerability addressed permits websites to deploy cross-site scripting attacks.

An issue in WebKit's handling of the parent and top objects may result in a cross-site scripting attack when visiting a maliciously crafted website. This update addresses the issue through improved handling of parent and top objects.

The second vulnerability permits arbitrary code execution when visiting certain maliciously-crafted websites.

A memory corruption issue exists in WebKit's handling of numeric character references. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved handling of numeric character references. Credit to Chris Evans for reporting this issue.

Safari 4.0.2 is available for OS X Leopard, OS X Tiger, and Windows (XP and Vista).

Top Rated Comments

(View all)

34 months ago
Just checked Software Update and it was on there. 28.1 MB.

Notes are...

This update is recommended for all Safari users and improves the stability of the Nitro JavaScript engine and includes the latest compatibility and security fixes.

For detailed information on the security content of this update, please visit this site: http://support.apple.com/kb/HT1222.


Hope this helps. I'm sick of being crashed on.
Rating: 0 Positives / 0 Negatives
34 months ago
Thank you. I've updated to 4.0.2 last night and it is pretty awesome; much better than the older Safari, especially in appearance.
Rating: 0 Positives / 0 Negatives
34 months ago

Thank you. I've updated to 4.0.2 last night and it is pretty awesome; much better than the older Safari, especially in appearance.


Appearance? What's different?
Rating: 0 Positives / 0 Negatives
34 months ago
I just updated to 4.0.2. I see no difference in the browser. The update was 40.2MB.
Rating: 0 Positives / 0 Negatives
34 months ago
Installed and all is good in the world. Not quite sure how I feel about the new purple theme.
Rating: 0 Positives / 0 Negatives
34 months ago
But does it put the tabs back on the top? I'm not leaving the beta until I can get that.
Rating: 0 Positives / 0 Negatives
34 months ago
i can only hope it solves the crashing issues ive had...:mad:
Rating: 0 Positives / 0 Negatives
34 months ago
Guess it's Leopard only as nothing is reported for SL.
Rating: 0 Positives / 0 Negatives
34 months ago

Guess it's Leopard only as nothing is reported for SL.



Im on snow leopard and when I downloaded it... and tried to install it said I can't because 10.5.8 is required
Rating: 0 Positives / 0 Negatives
34 months ago

Im on snow leopard and when I downloaded it... and tried to install it said I can't because 10.5.8 is required

... img snip ...


A bug perhaps?
Rating: 0 Positives / 0 Negatives

[ Read All Comments ]