Cupertino patches multiple flaws discovered in WebKit

Jul 1, 2014 07:44 GMT  ·  By

In tandem with OS X 10.9.4 and Security Update 2014-003, Apple today offers Safari 7.0.5 for Mavericks and Safari 6.1.5 for Lion and Mountain Lion customers, featuring patches for newly-found security issues.

Addressing more than a dozen separate WebKit flaws in the browser, Apple is offering two distinct updates, one for OS X Mavericks users, the other specifically tailored to OS X Lion and Mountain Lion.

The vulnerabilities discovered in WebKit are identical across all three OS X versions. For example, multiple corruption issues in the page rendering engine affected OS X Lion v10.7.5, OS X Lion Server v10.7.5, OS X Mountain Lion v10.8.5, and OS X Mavericks v10.9.3.

“Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution,” Apple says. The issues have been addressed through improved memory handling, according to the advisory.

Another flaw could lead to the disclosure of local file content by dragging a URL from a maliciously crafted website to another window. “This issue was addressed through improved validation of dragged resources,” according to the Mac maker.

Yet another WebKit vulnerability would allow a maliciously crafted website to spoof its domain name in the address bar. Apple improved encoding of URLs, thus patching the flaw.

Safari 7.0.5 is included in the Mavericks 10.9.4 update, whereas Safari 6.1.5 must be downloaded separately by users of OS X Lion and OS X Mountain Lion.

These are likely the last updates Safari will get before Apple releases the all-new version of the browser in OS X Yosemite this fall. In Yosemite, Safari gets a streamlined toolbar that displays your most important controls front and center, while at the same time giving you more room to view actual content.

Users will further get new ways to access their favorite sites, have more control over privacy matters, and manage their tabs with ease. An improved Nitro JavaScript engine will facilitate blazing-fast browsing, while the latest web standards are also implemented (such as WebGL).

You can open a window in Private Browsing mode and surf the web without having your browsing history saved, while other windows can remain in regular browsing mode.

Also in Yosemite, you can search the web directly in Spotlight and Safari will automatically summon suggestions from sources like Wikipedia, Bing, Maps, news, and iTunes, as well as results from the search engine you selected as default.

To use Safari 7.0.5 and Safari 6.1.5, your Mac needs at least OS X Lion (version 10.7).

Download Safari 7.0.5 for OS X Mavericks

Download Safari 6.1.5 for OS X Lion / Mountain Lion