Apple Once Again Blocks Java 7 Web Plug-in

Earlier this month, Apple took the unusual step of remotely blocking Oracle's Java 7 browser plug-in due to a major security vulnerability, using the "Xprotect" anti-malware system built into OS X to enforce a minimum version number that had yet to be released. Within days, Oracle updated Java to address the issue, with the new version number making the Java plug-in usable on OS X systems once more.

As noted by French site MacGeneration [Google translation] and the Apple discussion forums, Apple has once again blocked the Java 7 plug-in using Xprotect.

java_7_11_blacklist
The updated blacklist enforces a minimum Java plug-in version of 1.7.0_11-b22, while the latest version of the plug-in is 1.7.0_11-b21.

The exact reason for Apple's renewed block on the Java plug-in is unknown although reports immediately following the release of Update 11 earlier this month indicated that it fixed only one of the two bugs that contributed to the security vulnerability. In the wake of that news, cybersecurity officials recommended that most users disable Java even with the up-to-date plug-in installed.

Oracle Security Alert CVE-2013-0422 states that Java 7 Update 11 addresses this (CVE-2013-0422) and an equally severe, but distinct vulnerability (CVE-2012-3174). Immunity has indicated that only the reflection vulnerability has been fixed and that the JMX MBean vulnerability remains. Java 7u11 sets the default Java security settings to "High" so that users will be prompted before running unsigned or self-signed Java applets.

Unless it is absolutely necessary to run Java in web browsers, disable it as described below, even after updating to 7u11. This will help mitigate other Java vulnerabilities that may be discovered in the future.

If this continued issue is indeed the reason for the new block by Apple, it is unclear why the company waited several weeks to update its plug-in blacklist.

Top Rated Comments

jonatron Avatar
103 months ago

I've had Java disabled in my browser for the last several years, and I don't miss it at all. I think in all that time I have re-enabled it maybe once because there was an applet I actually wanted to run.

Just leave it turned off.


Classic if it doesnt affect me its not important.

This has stopped by company from using its finance system and staff are currently sat around twiddling their thumbs. Plus it took me an entire morning to work out what the issue was as there was no notification from Apple.

Thanks for your really useful advice!

I re-iterate what some others have said. THIS IS NOT ACCEPTABLE BEHAVIOUR from Apple and they need to sort this out pronto.
Score: 15 Votes (Like | Disagree)
ConCat Avatar
103 months ago

I've had Java disabled in my browser for the last several years, and I don't miss it at all. I think in all that time I have re-enabled it maybe once because there was an applet I actually wanted to run.

Just leave it turned off.

Some people actually need it in certain business environments. Apple really should quit doing this, and I mean now. If we want it disabled, we can disable it ourselves. How hard would it be to push the update to computers after Oracle updates Java with the security patch, not before?
Score: 12 Votes (Like | Disagree)
AppleScruff1 Avatar
103 months ago
Flash, Java, what's next? Internet access to Apple approved sites only?
Score: 9 Votes (Like | Disagree)
jwkay Avatar
103 months ago
Java is essential for the joint Norwegian bank login system BankID. If Apple has disabled this without a way of switching it back on, we are all locked out of our bank accounts!
Score: 8 Votes (Like | Disagree)
sonynair Avatar
103 months ago
They are also blocking Apple Java 1.6! Don't know where XProtect.meta.plist screenshot is from, but that is not what Apple pushed out this morning.

Here's what it really is!

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>JavaWebComponentVersionMinimum</key>
<string>1.6.0_37-b06-435</string>
<key>LastModification</key>
<string>Thu, 31 Jan 2013 04:41:14 GMT</string>
<key>PlugInBlacklist</key>
<dict>
<key>10</key>
<dict>
<key>com.macromedia.Flash Player.plugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>11.3.300.271</string>
</dict>
<key>com.oracle.java.JavaAppletPlugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>1.7.11.22</string>
</dict>
</dict>
</dict>
<key>Version</key>
<integer>2028</integer>
</dict>
</plist>


To re-enable Apple Java 1.6:

sudo /usr/libexec/PlistBuddy -c "Delete :JavaWebComponentVersionMinimum" /System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/XProtect.meta.plist

or

sudo defaults write /System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/XProtect.meta.plist JavaWebComponentVersionMinimum \"1.6.0_37-b06-434\"


To re-enable Oracle Java 1.7u11 edit the "/System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/XProtect.meta.plist" using vi in Terminal and change:

<string>1.7.11.22</string>
to:
<string>1.7.11.19</string>

I posted the block on Twitter when I noticed it this morning.
https://twitter.com/sonynair/status/296935103383347201

Hope that helps someone!
Score: 7 Votes (Like | Disagree)
sseaton1971 Avatar
103 months ago

Exactly None.
Apple should NOT BE BLOCKING HTTPS web sites that use Java Plugins.
Especially as Java 7 now has Java FX, with better Table handling and Charts.
It looks like Apple Envy, attempt to Force People to HTML5,
vs. a superior Technology: Java 7.


Since Java is not installed by default on the latest version of OS X, I don't think Apple should be blocking it at all. If a user wants to use Java, he or she should be able to do so. If a user wants to be protected, perhaps he or she can install some sort of malware app that also checks for possible Java exploits. I can see why Apple would use Xprotect for their own in-house version of Java, but this is not their baby anymore.

----------

Simple logic that you don't want to follow maybe?

The police "as prevention" may say do not go down that dark alley in this neighborhood, you may be robbed.

You can then decide if you go or not. You may want to go there , because your stuff is in a shed down there and you have not had any incidents.

The police will not block the access to that dark alley, so you can't go down there and get your stuff.

A pop up saying:

WARNING using JAVA is insecure to use or so

with an

I understand the risks (not that people do) continue

or

Cancel

This notification can be turned off in the preferences file.

Nobody here says that we do not appreciate actions by Apple to make our user experiences as safe as possible.

But, when somebody switches something off in my computer, I'd like to know.

Al Franken will get on this very shortly and the government will get involved.
Not necessarily a good thing, just wait and see:-)


Thank you... I agree wholeheartedly! I don't need Apple babysitting me. I hope this all gets resolved very soon.
Score: 6 Votes (Like | Disagree)

Top Stories

14

Apple Releases iOS 14.3 and iPadOS 14.3 With AirPods Max Support, ProRAW for iPhone 12 Pro, Apple Fitness+ and More

Monday December 14, 2020 10:00 am PST by
Apple today released iOS and iPadOS 14.3, updates that come over a month after the release of iOS and iPadOS 14.2, which brought new emojis, Intercom support, new wallpapers, and more. The iOS 14.3 update can be downloaded for free and it is available on all eligible devices over-the-air in the Settings app. To access the new software, go to Settings > General > Software Update. iOS 14.3...
iPhone 12 Pro Versus Alleged Samsung Galaxy S21 Plus e1607833895216

Hands-On Video Compares Unreleased Samsung Galaxy S21+ With iPhone 12 Pro

Sunday December 13, 2020 5:42 am PST by
Samsung's Galaxy S21 smartphone lineup is set to be released in 2021, and a new video shared on YouTube compares an alleged Samsung Galaxy S21+ with an iPhone 12 Pro. The back of the iPhone 12 Pro features precision-milled matte glass, while the back of the alleged Galaxy S21+ seems to be constructed from a plastic-like material. Additionally, the three distinct cameras of the Galaxy S21+...
iphone 12 pro max camera comparison google samsung

Camera Comparison: iPhone 12 Pro Max vs. Google Pixel 5 vs. Samsung Galaxy Note 20 Ultra

Thursday December 10, 2020 9:26 am PST by
Apple's iPhone 12 Pro Max has the most advanced camera technology in the iPhone lineup, but how does it match up to flagship smartphones from other companies? In our latest YouTube video, we compared the iPhone 12 Pro Max to the Google Pixel 5 and the Samsung Galaxy Note 20 Ultra to see the differences in camera quality. Subscribe to the MacRumors YouTube channel for more videos. The $1099...
jonyiveinterview

Apple CFO Luca Maestri and Jony Ive Reportedly Candidates for Ferrari CEO Position

Saturday December 12, 2020 7:27 pm PST by
Apple Chief Financial Officer Luca Maestri and former Chief Design Officer Jony Ive are reportedly candidates to be Ferrari's next CEO, reports Reuters, citing Italian media. Former Ferrari CEO Louis Camilleri departed the company last week citing personal reasons, and potential successors have since emerged, among those reportedly being Maestri and Ive. Additionally, former Vodafone CEO...
Top Stories 39 Feature

Top Stories: AirPods Max Announced, Apple Fitness+ Launch, Future Apple Silicon Chips

Saturday December 12, 2020 6:00 am PST by
The Apple product launches just keep on coming, with Apple this week introducing AirPods Max, the premium over-ear headphones that were rumored over the past few months under the "AirPods Studio" name. We also learned this week that Apple's Fitness+ subscription service will be launching on Monday, December 14 alongside the release of iOS 14.3 and related operating system updates, while we ...
apple fitness plus cnet

Apple Fitness+ Launches Today: Worthy Alternative to Peloton for Apple Watch Users

Monday December 14, 2020 6:55 am PST by
Apple's new Fitness+ workout service launches later today, and ahead of time, some media outlets and YouTube channels have shared their first impressions of the platform. We've gathered up some opinions and videos below. CNET's Vanessa Hand Orellana trying out Apple Fitness+ As a refresher, Fitness+ will provide users with access to a library of workout videos covering strength, yoga, dance,...
iphone 12 pro video colors

Kuo: iPhone 13 Models Won't Face Mass Production Delays Like iPhone 12 Lineup

Saturday December 12, 2020 8:18 am PST by
While the iPhone 12 lineup launched later than usual due to the COVID-19 pandemic, analyst Ming-Chi Kuo today forecasted that mass production of so-called iPhone 13 models with a new A15 chip will revert back to Apple's usual timeframe. In a typical year, Apple begins mass production of iPhones in the early summer, but reports indicated that mass production of iPhone 12 models did not begin...
Apple fitness plus feature

Here's When You Can Download iOS 14.3 and Start Using Apple Fitness+ [Update: Out Now]

Monday December 14, 2020 7:37 am PST by
Update: iOS 14.3 and Apple Fitness+ are now available. Our full coverage: Apple Releases iOS 14.3 and iPadOS 14.3 With AirPods Max Support, ProRAW for iPhone 12 Pro, Apple Fitness+ and More Apple Launches Fitness+, Three-Month Free Trial Now Available for New Apple Watch Owners Apple Releases watchOS 7.2 With Fitness+, Cardio Fitness Notifications, and More Apple Releases tvOS 14.3 for...
iphone 12 pro display video

iPhone 13 Pro Models Expected to Adopt LTPO Technology for 120Hz Display

Monday December 14, 2020 6:10 am PST by
Two out of four iPhone 13 models set to launch next year (presumably the Pro models) will use OLED displays with low-power LTPO technology, paving the way for a 120Hz refresh rate, according to Korean website The Elec. The report claims that Samsung and LG will remain Apple's primary suppliers of OLED displays, which are expected to be used across the entire iPhone 13 lineup, with Chinese...
iphone 12 colors

iPhone 12 Colors: Deciding on The Right Color

Thursday November 5, 2020 8:35 am PST by
The iPhone 12 and iPhone 12 Pro arrived last month in a range of color options, with entirely new hues available on both devices, as well as some popular classics. The 12 and 12 Pro have different color choices, so if you have your heart set on a particular shade, you might not be able to get your preferred model in that color. iPhone 12 mini and iPhone 12 The iPhone 12 mini and iPhone 12 are ...