NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Apple / Mac

Mac


Personal Data at Risk with Safari RSS Vulnerability

An attempt to retrieve personal info requires the use of a malicious web page

By Filip Truta, Apple News Editor

13th of January 2009, 08:55 GMT

Adjust text size:


RSS feed service icon
Enlarge picture
A hole in Safari's handling of RSS feeds could allow an attacker to capture a user's personal information, cookies, or even passwords, Brian Mastenbrook reveals. Brian is credited with discovering multiple vulnerabilities in Mac OS X.

“I have discovered that Apple's Safari browser is vulnerable to an attack that allows a malicious web site to read files on a user's hard drive without user intervention,” Mastenbrook writes. “This can be used to gain access to sensitive information stored on the user's computer, such as emails, passwords, or cookies that could be used to gain access to the user's accounts on some web sites.”

According to Brian, the vulnerability has been acknowledged by Apple. Reportedly, “All users of Mac OS X 10.5 Leopard who have not changed their feed reader application preference from the system default are affected, regardless of whether they use RSS feeds or use a different web browser (such as Firefox).”

Those using Apple's web browser on Windows machines are also affected. However, if they only have it installed, but use a different application to browse the web, Windows users are on the safe side. Thus, the workaround for Windows users is very simple: just use a different web browser (Firefox, Opera etc.). On the Mac side, the situation is a tad more serious. Nevertheless, Mac users also have a workaround for the issue: “Simply set an alternative RSS feed handler,” Brian says. Instructions on how to do that are also provided.

RSS feeders, such as NetNewsWire (free) and NewsFire, are available for download. A reader that complements the Mac's appearance and functionality is Vienna, the open source, freeware RSS reader with support for RSS/Atom feeds, article storage, and management via a SQLite database. Whichever app you choose for the task of fetching you the latest news, remember not to leave RSS feed preferences set to default. That is, not until Apple fixes the issue.

TAGS:

RSS | RSS feed | vulnerability | security | Safari
Read by 789 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Google Chrome Needs 'Common Code' on Mac and Linux

10 Must-Have Firefox Extensions

1Password 2.9.8 Beta 1 Adds Hidden Pref, Improves Search

OnyX 2.0.1 Adds Support for 'New Web Browsers'

Snow Leopard Videos, Screens Leaked

Security Update 2008-008 Available for All Mac Users

Softpedia Recommended Mac Apps of the Week – 14.12.2008

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM