Secunia ranks Apple first in software insecurity, Safari said to have AutoFill vulnerability
Posted in: adobe, Apple, HP, Microsoft, security, Software, Today's ChiliOne vulnerability that is potentially serious, however, is an issue with Safari’s AutoFill feature recently discovered by Jeremiah Grossman of WhiteHat Security. According to Grossman, a malicious website can exploit the feature to pull data from a user’s address book without their knowledge, which has been demonstrated to take “mere seconds” by a bit of proof of concept code (you can try out yourself if you’re feeling trusting). Grossman also says he’s informed Apple of the vulnerability but hasn’t received a response, and suggests that the only “fix” in the meantime is to turn off the AutoFill feature completely.
Update: AllThingsD has a statement from Apple on the AutoFill issue — a spokesperson says “we take security and privacy very seriously,” and that, “we’re aware of the issue and working on a fix.”
Secunia ranks Apple first in software insecurity, Safari said to have AutoFill vulnerability originally appeared on Engadget on Thu, 22 Jul 2010 15:31:00 EDT. Please see our terms for use of feeds.
Permalink Ars Technica, 9 to 5 Mac |
Secunia (PDF), Jeremiah Grossman | Email this | Comments
Post a Comment