Got a tip for us? Share it...

Safari 5.0.1 and 4.1.1 Address AutoFill Security Flaw


As noted in the security documentation accompanying today's release, Safari 5.0.1 and 4.1.1 address an AutoFill security flaw disclosed last week that could allow a malicious site to obtain a user's Address Book information, including name, company affiliation, city/state/country, and email address.

Impact: Safari's AutoFill feature may disclose information to websites without user interaction

Description: Safari's AutoFill feature can automatically fill out web forms using designated information in your Mac OS X Address Book, Outlook, or Windows Address Book. By design, user action is required for AutoFill to operate within a web form. An implementation issue exists that allows a maliciously crafted website to trigger AutoFill without user interaction. This can result in the disclosure of information contained within the user's Address Book Card. To trigger the issue, the following two situations are required. First, in Safari Preferences, under AutoFill, the "Autofill web forms using info from my Address Book card" checkbox must be selected. Second, the user's Address Book must have a Card designated as "My Card". Only the information in that specific card is accessed via AutoFill. This issue is addressed by prohibiting AutoFill from using information without user action. Devices running iOS are not affected. Credit to Jeremiah Grossman of WhiteHat Security for reporting this issue.

Grossman reported the issue to Apple on June 17th, but went public with his disclosure last week in order to alert customers after failing to receive significant response from Apple. After Grossman's public disclosure, Apple acknowledged the issue and promised that it was working on a fix.

Top Rated Comments

(View all)

20 months ago
Hi,

I unclicked those boxes years ago.

s.
Rating: 0 Positives / 0 Negatives
20 months ago
but does this happen with the usernames and passwords stored in safari??
Rating: 0 Positives / 0 Negatives
20 months ago
I didn't even know there was an issue.. But im glad its fixed!
Rating: 0 Positives / 0 Negatives
20 months ago
great, back to safari

this firefox beta 4 is painfully slow
Rating: 0 Positives / 0 Negatives
20 months ago
They had to patch this quickly because it's so easy to exploit that someone was bound to do it at Black Hat.
Rating: 0 Positives / 0 Negatives
20 months ago
I'm still confused how autofilling the form can give the site access to your data. UNless the data is submitted. Just typing data into a form field doesn't send the data to the server. Or does the site wait for it to be autofilled and then it triggers the submit itself?
Rating: 0 Positives / 0 Negatives
20 months ago

I'm still confused how autofilling the form can give the site access to your data. UNless the data is submitted. Just typing data into a form field doesn't send the data to the server. Or does the site wait for it to be autofilled and then it triggers the submit itself?


I'm no web developer (Mac/iOS instead) but I'm pretty sure that you can get the user's typing before they submit a form. JavaScript events when the text field changed or something like that. Google does this, for instance, to show search results.
Rating: 0 Positives / 0 Negatives
20 months ago
Awesome.

By the way, it's an issue with ALL browsers, not just Safari.

Where're the other vendor's browser security updates?
Rating: 0 Positives / 0 Negatives
20 months ago
Let's hope that the dns issues have been fixed. I was sick of the " can't connect to server" messages.
Rating: 0 Positives / 0 Negatives
20 months ago
Quite a confusing headline there: "Safari 5.0.1 and 4.1.1 Address AutoFill Security Flaw"

Same in the first paragraph — especially when address and Address have two different meanings. Could you not just use recognise or warn of in place of address?

The readability of this site is fairly poor. Please employ a proper journalist.
Rating: 0 Positives / 0 Negatives

[ Read All Comments ]