Secunia Flags ‘Highly Critical’ Safari Zero Day Flaw

A zero-day vulnerability in Apple’s Safari browser could expose millions of Windows users to drive-by download malware attacks.  The flaw is currently unpatched.

A zero-day vulnerability in Apple’s Safari browser could expose millions of Windows users to drive-by download malware attacks.  The flaw is currently unpatched.

According to an alert from Secunia, the issue is rated “highly critical” because of the risk of remote code execution attacks that can lead to complete system takeover.

From the advisory:

The vulnerability is caused due to an error in the handling of parent windows and can result in a function call using an invalid pointer. This can be exploited to execute arbitrary code when a user e.g. visits a specially crafted web page and closes opened pop-up windows.
The vulnerability is confirmed in Safari version 4.0.5 for Windows. Other versions may also be affected

The vulnerability is caused due to an error in the handling of parent windows and can result in a function call using an invalid pointer. This can be exploited to execute arbitrary code when a user e.g. visits a specially crafted web page and closes opened pop-up windows.

The vulnerability is confirmed in Safari version 4.0.5 for Windows. Other versions may also be affected, the company warned.

Suggested articles

Discussion

  • william6789 on

    Millions of people have been working with window OS daily and the vulnerability of Apple's Safari browser is a serious factor for them who are browsing it daily.Its shortcoming has caused a great effect that can be a serious threat in the unleaking of data in the hands of hackers.real estate evansville indiana

  • KaylaSho on

    Over the last two weeks, security researchers have reported eight different zero-day vulnerabilities in Apple’s Safari browser. I found this information while reading free essays.

    Details of these vulnerabilities, all rated “high risk,” have been sold to Tippingpoint’s Zero Day Initiative (ZDI), a program that purchases the rights to vulnerability information in exchange for exclusivity to broker fixes with affected vendors.

  • alice_viers on

    does anyone actually use safari on windows?term papers

  • Anonymous on

    Nonsense, all of this.  Everyone knows Apple products don't suffer from viruses. (snicker)

  • Anonymous on

    I'm not such a fan of safari, I used it for about 6 months but it turned out to be a very problematic time for me, then I switched to chrome and finally I can browse web without any problems.

Subscribe to our newsletter, Threatpost Today!

Get the latest breaking news delivered daily to your inbox.