January 13, 2009

Vulnerability in Safari discovered, RSS handling to blame

hackerWe have received word from Brian Mastenbrook, who has discovered security vulnerabilities with Apple stuff in the past, that a severe vulnerability exists in the Safari browser.  Brian says there is a possibility that a hacker can take control of any system that runs Safari due to a hole in the way Safari handles RSS feeds.  Brian is not publishing specifics of the security hole to prevent exploitation but he has acknowledgement from Apple that the problem exists.

Mac users can simply change the Safari preferences to use another program to handle RSS feeds.  Windows users who use Safari are not so lucky and it is suggested they use a different browser until Apple issues a fix for the problem.

RECENT STORIES:
Enjoy this post? Receive more jkOnTheRun content for FREE by subscribing to the RSS feed!

3 Responses to “Vulnerability in Safari discovered, RSS handling to blame”

  • Jake says:

    I’d recommend that Windows users use another browser until Apple stop being so arrogant and get rid of that Apple OS X theme they insist on wrapping around all their software.

    As if it’s not enough that they produce crap software (Quicktime, iTunes, etc.) they also make it as ugly as possible.

  • Oliver says:

    I see little reason to use Safari on Windows given the alternatives. And I see even less reason to use Safari for RSS feeds.

    @Jake — thanks, looks like I am not the only one who believes in the “when in Rome, do as the Romans do…” concept. I hate the L&F of Apple’s Windows apps. I wonder what they’d say if I submitted an iPhone app to them for approval that, heaven forbid, looked like a PalmOS app.

  • straw000 says:

    I dont use Safari for RSS reading, but NewFire so I should be quite safe : )

Post a reply

RSS and Mobile-Friendly View

Daily E-mail Newsletter

Enter your email address:

Sponsor Gallery

Become a sponsor »

Contributors

Kevin C. Tofel

James Kendrick

Kevin's gear   JK's gear

Awards

Microsoft MVP Awardees

CNET100 2004Weblog Awards
2004ReadersChoice 2004_BoardOfExperts
StatCounter