Skip to main content

Homeland Security Warns of Apple’s Safari Security Bug

Yes, Apple users, it is a sad truth, but you have security flaws too. The Danish security firm Secunia has discovered a vulnerability in the Safari web browser that it has labeled “highly critical”, the most serious security rating the firm can give. The flaw has been confirmed by the United States Computer Emergency Readiness Team, a Department of Homeland Security, and an advisory has been issued.

So far the bug is specifically targeting Windows operating systems, but Apple’s OS may also be affected. The flaw allows hackers to access key information when the user opens webmail services like Gmail, Hotmail, or Yahoo. The hacker can then log user data including passwords and even credit card information. The warning also claims that specially crafted websites can grant hackers access, as can closing specific pop ups.

The issue is specifically related to a badly coded section in Safari. Apple has met the security flaw with the same forthcoming attitude and tenacity that they meet all security flaws – in other words they have remained silent on the subject and refuse to comment. No patch has been released, and it is anyone’s guess when or if there will be one. Until there is, Secunia recommends that you “Do not visit untrusted web sites or follow links from untrusted sources. Do not authenticate to sites that use HTTP basic authentication and use redirections to different domains.”

The Safari browser has been plagued with security issues since its release, and Apple has faced criticism for releasing patches without announcing the security flaw that the patch is for. In March, Apple released 16 patches for Safari, including 10 that specifically affected Mac OS X.

Editors' Recommendations

Topics
Ryan Fleming
Former Digital Trends Contributor
Ryan Fleming is the Gaming and Cinema Editor for Digital Trends. He joined the DT staff in 2009 after spending time covering…
Vital security update for Apple devices takes only a few minutes to install
iPhone 14 Pro Max in hand.

UPDATE: Just hours after rolling out the security update, Apple has pulled it after users began experiencing compatibility issues with Safari for sites such as Instagram and Facebook. If you've already installed the update, you can downgrade on iPhone and iPad by going to Settings, then General. Select About and then OS version. Finally, tap Remove Security Response.

For Mac, select the Apple logo top left and then System Settings. Next, select General, and then About. Under macOS, select the "i" (information) button located beside the OS version. Where it says Last Security Response, select the Remove & Restart button, and then Remove Response and Restart in the prompt.

Read more
This critical exploit could let hackers bypass your Mac’s defenses
A hacker typing on an Apple MacBook laptop while holding a phone. Both devices show code on their screens.

Microsoft has discovered a critical exploit in macOS that could grant hackers easy access to your Mac’s most important data. Dubbed ‘Migraine,’ it shows why it’s vital to update your Mac as soon as possible.

Migraine is so damaging because it can bypass Apple’s System Integrity Protection, or SIP for short. SIP is enabled by default on modern Macs and works by sandboxing sensitive parts of the computer from outside meddling. Only processes that are signed by Apple (or those with special privileges, like Apple installers) are allowed to alter something guarded by SIP.

Read more
Google just made this vital Gmail security tool completely free
The top corner of Gmail on a laptop screen.

Hackers are constantly trying to break into large websites to steal user databases, and it’s not entirely unlikely that your own login details have been leaked at some point in the past. In cases like that, upgrading your password is vital, but how can you do that if you don’t even know your data has been hacked?

Well, Google thinks it has the answer because it has just announced that it will roll out dark web monitoring reports to every Gmail user in the U.S. This handy feature was previously limited to paid Google One subscribers, but the company revealed at its Google I/O event that it will now be available to everyone, free of charge.

Read more