Apple Patches Safari Browser Holes
Apple on Thursday issued updates for its Safari Web browser to fix more than two dozen vulnerabilities that left the browser open to Web-based attacks.
The company released Safari versions 5.0.3 and 4.1.3 for Mac OS X and Windows XP SP2, Vista and Windows 7. The updated versions fix 27 reported vulnerabilities in the Safari Webkit component that made Safari users vulnerable to Web based attacks that could crash the browser or, in a worst case scenario, allow attackers to run their own malicious code on vulnerable systems.
Apple published a knowledge base article describing the updates to Safari. US-CERT issued an advisory on Friday suggesting that Safari users read the knowledge base article and apply the updates.
WebKit is used to render Web page content within browsers, including hyperlinking, browser history and so on. The component is native to Safari and is separately managed as an open source project that has been ported to other platforms as well. Vulnerabilities in WebKit have recently snagged other platforms, as well, including Google's Android Mobile O.S. researcher MJ Keith of Alert Logic published code to exploit a known WebKit vulnerability in Android's 2.0 and 2.1 operating systems. That hole has been fixed in the latest version of Android, 2.2, but only a minority of Android phones in use have upgraded to the latest version, according to Google data.
Commenting on this Article is closed.
Today's Most Popular
- Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest
- Dear Jailbreaker, Apple Wants to Have a Word with You
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
- OPINION: Are Anonymous Members Forged in the Crucible of IT Compliance?
- White House Security Czar Howard Schmidt Retiring
Most Commented Stories
-
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops (5)
-
White House Security Czar Howard Schmidt Retiring (3)
-
Staggering Increase in Android Malware Variants, Trojan Apps (2)
-
Author of LilyJade Facebook Plugin Ignores Facebook Cease-and-Desist (2)
-
New P2P Zeus Variant Targets Popular Sites with Bogus Offers (1)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



