Open Source Software Engineer Reports Vulnerability in Safari RSS Feeds

In a post to his blog on Sunday, open source software engineer Brian Mastenbrook stated he's located a vulnerability in the Safari web browser for the Mac OS X and Windows operating systems that could compromise a user's files and passwords if exploited.

"Safari ... is vulnerable to an attack that allows a malicious web site to read files on a user's hard drive without user intervention," Mastenbrook wrote.  "This can be used to gain access to sensitive information stored on the user's computer, such as emails, passwords, or cookies that could be used to gain access to the user's accounts on some web sites."

Mastenbrook then advises that users change their default RSS reader preference to another feed reader, such as the one embedded in Apple's Mail program or NetNewsWire.

Where Windows users are concerned, Mastenbrook's blog entry suggests that users rely on an alternate web browser until the security hole is patched.

Though not a widely known name outside security circles, Mastenbrook is currently credited with no fewer than four mentions by name in previous security updates and fixes.