The Mac Observer

Open Source Software Engineer Reports Vulnerability in Safari RSS Feeds

January 13th, 2009 at 11:15 AM - News by Chris Barylick

In a post to his blog on Sunday, open source software engineer Brian Mastenbrook stated he's located a vulnerability in the Safari web browser for the Mac OS X and Windows operating systems that could compromise a user's files and passwords if exploited.

"Safari ... is vulnerable to an attack that allows a malicious web site to read files on a user's hard drive without user intervention," Mastenbrook wrote.  "This can be used to gain access to sensitive information stored on the user's computer, such as emails, passwords, or cookies that could be used to gain access to the user's accounts on some web sites."

Mastenbrook then advises that users change their default RSS reader preference to another feed reader, such as the one embedded in Apple's Mail program or NetNewsWire.

Where Windows users are concerned, Mastenbrook's blog entry suggests that users rely on an alternate web browser until the security hole is patched.

Though not a widely known name outside security circles, Mastenbrook is currently credited with no fewer than four mentions by name in previous security updates and fixes.

 

 

2 Observer Comments

I wonder how soon it will before Apple has a security update for this.

   Actions Original Workaround Not Sufficient said on January 14th, 2009 at 1:35 PM:

“The original version of this page contained a simple workaround for this issue which I believed would protect users against this problem. I have since discovered (on 13 January 2009) that changing the default RSS feed reader application in Safari does not correctly disassociate Safari from all RSS feed URLs. The workaround section of this post has been updated with additional information. I regret that what initially appeared to be a simple workaround is now substantially more complicated and requires the installation of third-party software to perform.”

Page 1 of 1 pages
Login. Need an account? Register here.



Auto-login on future visits

Show my name in the online users list

Forgot your password?


Commenting is not available in this section entry.
 

Recent Headlines - Updated February 10th

Wed, 9:45 AM
Analysis - iPad Costs Could ‘Leave Room for Price Cuts’
9:00 AM
TMO Appearances - Jeff Gamet Joins MacJury Live at Macworld Expo 2010
9:00 AM
Analysis - iPad’s Business Use ‘Underestimated,’ Says Financial Writer
8:00 AM
Analysis - Love It or Leave It: Extremist Views on iPad Obscure the Important Points
7:30 AM
TMO Appearances - Ted Landau Shares Troubleshooting Tips at Macworld Expo
Tue, 9:09 PM
Games - Gameloft’s GT Racing Motor Academy Arrives at App Store
6:27 PM
iPad - Apple Job Posting Hints at a Camera in Future iPads
6:22 PM
Product News - Apple Releases Digital Camera RAW Compatibility Update 3.0
6:18 PM
Product News - Apple Updates iLife ‘09 with Aperture 3 Support, Slideshow Performance
4:53 PM
News - Google Introduces “Buzz” Social Information Sharing Service
4:19 PM
Just a Thought - iPad: A Reason For Being
3:28 PM
News - Google Lowers Nexus One “Equipment Recovery Fee” to $150
 

The Mac Observer Reader Specials

Apple Stock Quote

  • AAPL: $196.03. Change: -0.16.
  • (Prices delayed up to 20 minutes.)
  • Discuss in our Apple Finance Board

Hot Topics

TMO Express

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday. Find out more!

Top Deals From DealBrothers.com

Recent Features

Support The Mac Observer

We noticed you may be running AdBlock on your computer. It takes real money to run this site and to deliver the news, tips, and opinions you love to read.

If you wish to block the ads that pay for the creation of our content, we ask that you instead support TMO Directly, either with a $5 monthly recurring contribution, or a one-time donation of any amount of your choice. Thanks!

Subscribe with Paypal Donate with Paypal