Safari vulnerability

pbpb
Posted:
in Mac Software edited January 2014
Just found this proof of concept for a Safari vulnerability. It says it can execute code remotely.



Quote:

A new vulnerability has been discovered Using the runscript function of the MacOSX's Help.app application, which is callable from Safari, we can execute code remotely.



This proof of concept is simply a real life example of the vulnerability. It will not damage or really compromise your computer: the source script is included with the code which will be executed.



Since I am not right now on a Mac, can anyone try it and tell us what happens? The severity of the exploit is considered high. Is this true?

Comments

  • Reply 1 of 6
    pbpb Posts: 4,255member
    Never mind, the vulnerability is being discussed at macnn, and it seems to be pretty big. Microsoft grade I would say !
  • Reply 2 of 6
    costiquecostique Posts: 1,084member
    OMFG! I didn't even know that WebKit supports launching AppleScripts. It simply must be removed. Nay, web browsers must not be able to execute or launch anything by definition. Really scary.
  • Reply 3 of 6
    opuscroakusopuscroakus Posts: 317member
  • Reply 4 of 6
    macsrgood4umacsrgood4u Posts: 3,007member
    Check Software Update for the download.
  • Reply 5 of 6
    stoostoo Posts: 1,490member
    Was that about a week from annoucement to fix? Not too shabby Apple, except for the Software Update timeouts. I guess that the world and their dog are downloading it.
  • Reply 6 of 6
    aquaticaquatic Posts: 5,602member
    Quote:

    OMFG! I didn't even know that WebKit supports launching AppleScripts. It simply must be removed. Nay, web browsers must not be able to execute or launch anything by definition. Really scary.





    |



    Are you being serious? I think this is a great convenience. And it isn't really a vulnerability, I mean computers do what you tell them. In Prefs it asks if you want to let Safari "process safe downloads." That's what this whole issue is right? Well if you don't want Safari to do this, just uncheck that. What's so bad about that?
Sign In or Register to comment.