Apple Once Again Blocks Java 7 Web Plug-in
Earlier this month, Apple took the unusual step of remotely blocking Oracle's Java 7 browser plug-in due to a major security vulnerability, using the "Xprotect" anti-malware system built into OS X to enforce a minimum version number that had yet to be released. Within days, Oracle updated Java to address the issue, with the new version number making the Java plug-in usable on OS X systems once more.
As noted by French site MacGeneration [Google translation] and the Apple discussion forums, Apple has once again blocked the Java 7 plug-in using Xprotect.

The updated blacklist enforces a minimum Java plug-in version of 1.7.0_11-b22, while the latest version of the plug-in is 1.7.0_11-b21.
The exact reason for Apple's renewed block on the Java plug-in is unknown although reports immediately following the release of Update 11 earlier this month indicated that it fixed only one of the two bugs that contributed to the security vulnerability. In the wake of that news, cybersecurity officials recommended that most users disable Java even with the up-to-date plug-in installed.
Oracle Security Alert CVE-2013-0422 states that Java 7 Update 11 addresses this (CVE-2013-0422) and an equally severe, but distinct vulnerability (CVE-2012-3174). Immunity has indicated that only the reflection vulnerability has been fixed and that the JMX MBean vulnerability remains. Java 7u11 sets the default Java security settings to "High" so that users will be prompted before running unsigned or self-signed Java applets.
Unless it is absolutely necessary to run Java in web browsers, disable it as described below, even after updating to 7u11. This will help mitigate other Java vulnerabilities that may be discovered in the future.
If this continued issue is indeed the reason for the new block by Apple, it is unclear why the company waited several weeks to update its plug-in blacklist.
Popular Stories
While the iPhone 18 Pro and iPhone 18 Pro Max are not expected to launch for more than five more months, there are already plenty of rumors about the devices.
It was initially reported that the iPhone 18 Pro models would have fully under-screen Face ID, with only a front camera visible in the top-left corner of the screen. However, the latest rumors indicate that only one Face ID component...
We're long overdue for an Apple TV update, and there have been rumors about an imminent refresh since late last year. It's now sounding like we're not going to get a new version for several months because of Siri delays. If you're holding out for a new model, here's a recap on what to expect when it eventually comes out so you can decide whether to continue to wait, or buy now.
Design
Apple ...
Apple's CarPlay system for accessing iPhone apps on a vehicle's dashboard screen received three popular apps this week: ChatGPT, Google Meet, and Audiomack.
CarPlay Ultra in an Aston Martin
In addition, WhatsApp is beta testing a revamped CarPlay app that will improve upon the basic Siri-based functionality that was previously available.
Make sure you have the latest version of each app...
Popular Stories
While the iPhone 18 Pro and iPhone 18 Pro Max are not expected to launch for more than five more months, there are already plenty of rumors about the devices.
It was initially reported that the iPhone 18 Pro models would have fully under-screen Face ID, with only a front camera visible in the top-left corner of the screen. However, the latest rumors indicate that only one Face ID component...
We're long overdue for an Apple TV update, and there have been rumors about an imminent refresh since late last year. It's now sounding like we're not going to get a new version for several months because of Siri delays. If you're holding out for a new model, here's a recap on what to expect when it eventually comes out so you can decide whether to continue to wait, or buy now.
Design
Apple ...
Apple's CarPlay system for accessing iPhone apps on a vehicle's dashboard screen received three popular apps this week: ChatGPT, Google Meet, and Audiomack.
CarPlay Ultra in an Aston Martin
In addition, WhatsApp is beta testing a revamped CarPlay app that will improve upon the basic Siri-based functionality that was previously available.
Make sure you have the latest version of each app...