Apple plugs 'gone in 30 seconds' Safari flaw

Apple has released another round of security patches for its Web browser this week, targeting a vulnerability which allowed a MacBook Air to be hacked and two flaws in the Windows-only version of Safari.

The company released the patches this week after a number of vulnerabilities were discovered in the browser recently, including one which allowed a security expert to take control of a MacBook Air at the CanSecWest security conference in March, where a malicious Web site was used to exploit the flaw.

"The interesting thing about this is that it took a team of hardcore security experts to crack this," said James Turner, security analyst for research firm IBRS.

"From Apple's perspective, it's been good to have that flaw publicised and to appear to have done something about it within a relatively short space of time," he noted.

An Apple spokesperson declined to comment on the flaw, telling ZDNet.com.au: "What happened at that forum was specific to the forum, Apple won't discuss that."

Recent research by IBM found Apple flaws made up 3.2 percent of all vulnerabilities reported in 2007, putting the company in second place behind Microsoft, with 3.7 percent.

Apple's most recent patch batch also fixed vulnerabilities in Safari for Windows. An Apple spokesperson told ZDNet.com.au today that the company would not comment on what the cause or effects of these flaws were.

According to IBRS analyst Turner, the Windows flaw was unlikely to have affected many users and even fewer organisations, given that few if any are likely to have deployed Safari as a standard browser.

"Apple will of course continue to use the Polaroid model and push their own browser on their own hardware, which in turn means that more and more attention will be focused on them," he said.

"For a couple of years now industry pundits have been saying that as Apple's market share grows they will be targeted more often," Turner said. "Microsoft's been in the spotlight so long now, but now someone else is sharing the stage, and I think they'd [Microsoft] be happy about that."

According to Apple, in the first quarter of last year it shipped 2.3 million Macs, representing 44 percent growth year-on-year.

Advertisement

Talkback 2 comments

  1. Great Job Anonymous -- 20/04/08

    Great job to the people who exposed this flaw and great job to apple for actually addressing security issues with their operating system. As a mac user I feel like I don't actually need a virus scanner because apple care enough to fix these problems.

    1. It will only be a matter of time Anonymous -- 21/04/08

      Apple will become targeted more and more if they continue to gain popularity. As for the caring part about patches. All companies aim to fix flaws as soon as possible when they are brought to their attention.

Add your opinion


ZDNet's CIO Vision Series

Customs | Murray Harrison, CIO

Australian Customs CIO Murray Harrison dislikes SLAs and runs away if a vendor talks to him about innovation. In this interview, he also explains why getting excited about gadgets can be dangerous and talks about how Customs' outsourcing strategy has evolved.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Munir Kotadia iPhone suckers test our patience
    So how many of you have bought a 3G iPhone? Do you feel like a sucker? If you don't, maybe you will once your first bill arrives.
  • Array Westpac bank: AVG's toughest competitor
    The next time you're buying antivirus software, don't go direct to Symantec or McAfee. Don't download free antivirus. And definitely don't see Harvey Norman. Ask your bank — they're quite literally giving the stuff away.
  • Array Will you manage in the exabyte era?
    Mammoth growth in storage volumes is a fact of life, but even so it's helpful to pause occasionally and try and work out whether our information strategies have fallen hopelessly out of step with the pace of technological growth and changes in costs.
  • More blogs »

Tags

Back to top

Featured