All the latest UK technology news, reviews and analysis

Security flaw hits Safari on Windows

by Tom Sanders in California

12 Jun 2007

Comment: 1

  • Tweet this
Apple bug

Security researcher Aviv Raff claims to have found the first security vulnerability in Apple's Safari browser on Windows only hours after the software was released.

Raff tested the application against a standard browser security testing tool.

"A first glance at the debugger showed me that this memory corruption might be exploitable. Although I'll have to dig more to be sure of that," he wrote on his blog.

Apple unveiled a beta of a Windows version of its Safari web browser on Monday. The final product is scheduled for release in October.

In a keynote presentation at Apple's Worldwide Developers Conference in San Francisco, chief executive Steve Jobs claimed that the browser would run up to twice as fast as Microsoft's Internet Explorer, but did not mention Internet Explorer's security record.

Apple lists the browser's security as one of 12 reasons "why you'll love Safari" and adds that "Apple engineers designed Safari to be secure from day one ".

Raff worked on the "Month of Apple bugs" earlier this year, during which researchers published details on a slew of vulnerabilities in the software.

It was intended to challenge Apple's security record. He took the company's boasting about Safari's security as a personal challenge.

"So I've decided to take it for a test drive and ran Hamachi. I wasn't surprised to get a nice crash few minutes later," he wrote. Hamachi is a tool that tests a browser's integrity.

"Don't you hate those pathetic claims?" he said in the closing of his post in reference to Apple's marketing speak.

Apple did not immediately respond to a request for comment.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Field/Site Engineering Manager/Leader

Field/Site Engineering Manager/Leader Brief: Polar...

Product Manager, Open Repository (ref:BMC/PMR)

Product Manager, Open Repository (ref:BMC/PMR) End...

Java/JEE Software Developer-Dotcom/eCommerce Software House

Java/J2EE Software Developer/Programmer - Dotcom/ eCommerce...

Field/Site Engineering Manager/Leader

Field/Site Engineering Manager/Leader Brief: Polar...

To send to more than one email address, simply separate each address with a comma.