Feeds

Tight-lipped Apple fixes Safari autosnoop bug

Black Hat talk preempted

  • alert
  • submit to reddit

Choosing a cloud hosting partner with confidence

Black Hat Apple has fixed a flaw in Safari that exposed user names, email addresses, and other sensitive information when the browser visited booby-trapped websites.

The update, which included an unrelated fix for a separate information disclosure vulnerability in Safari, comes a day before security researcher Jeremiah Grossman is scheduled to show attendees of the Black Hat Security conference in Las Vegas how to trick the AutoFill feature in the Apple browser into turning over detailed user information with no user input except visiting a particular website. Grossman said previously he had brought it to Apple's attention privately but received no response from the company.

In a bulletin published Tuesday, Apple said it had squashed the bug by prohibiting AutoFill from using user information without user action. Grossman, who is scheduled to speak about the vulnerability on Wednesday, said he hasn't had a chance to test the patch to see if it completely fixes the bug.

The vulnerability allowed webmasters to add simple code to their sites that siphoned highly personal information stored in a user's Mac or Windows address book. By default, the user's full name, email address, location, employer, and other information were free for the taking, and all that was required is that the information already be entered in the "My Card" record of address books included in OS X, Windows, or Outlook address books.

Apple's prompt action is testament to the power of full disclosure, which argues users are best protected when detailed information about vulnerabilities are widely disclosed. Many companies argue details should be shared only privately with the software maker until a patch is issued. Apple didn't publicly acknowledge the flaw until mainstream publications such as The New York Times and The Wall Street Journal published articles about the flaw, calling into question of the wisdom of so-called responsible disclosure.

Separately, Apple fixed a separate Safari bug that allowed webmasters to download system files using a specially designed RSS feed. The fix was credited to Billy Rios, a security researcher who recently left Microsoft for Google. Apple also patched more than a dozen bugs in Webkit. ®

Beginner's guide to SSL certificates

More from The Register

next story
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
The Heartbleed Bug: how to protect your business with Symantec
What happens when the next Heartbleed (or worse) comes along, and what can you do to weather another chapter in an all-too-familiar string of debilitating attacks?