Security experts are warning users of Apple's Safari web browser to upgrade to the latest version immediately or risk hackers being able to run malicious code on their computers.
Apple yesterday released a new version of its flagship browser – 4.0.3 – featuring fixes to stability and compatibility problems, but also to patch six vulnerabilities.
These included buffer overflow issues and a problem with Safari's Top Sites feature, which could facilitate a phishing attack by allowing a "malicious website to promote arbitrary sites into the Top Sites view", said Apple.
Graham Cluley, senior technology consultant for security vendor Sophos, argued that users must update as soon as possible to the new version of Safari, whether they run it on a Microsoft or Apple-based operating system.
"Don't think you can get away with not updating if you run Safari on Windows XP or Vista, because two of the security patches only apply to the version of Apple's browser that runs on Microsoft's operating system," he wrote.
"It doesn't matter whether you run Safari on Mac OS X or Windows computers, it's important that you apply these security patches detailed in a security advisory on Apple's website."
Apple fixes more Safari security flaws
By
Phil Muncaster
on Aug 13, 2009 9:10AM
Got a news tip for our journalists? Share it with us anonymously here.
Partner Content

Build cybersecurity capability with award winning Fortinet training from Ingram Micro

Secure, integrated platforms enable MSPs to focus bringing powerful solutions to customers

Kaseya Dattocon APAC 2024 is Back

Channel can help lead customers to boosting workplace wellbeing with professional headsets

How NinjaOne Is Supporting The Channel As It Builds An Innovative Global Partner Program
Sponsored Whitepapers
-1.jpg&w=100&c=1&s=0)
Stop Fraud Before It Starts: A Must-Read Guide for Safer Customer Communications

The Cybersecurity Playbook for Partners in Asia Pacific and Japan

Pulseway Essential Eight Framework

7 Best Practices For Implementing Human Risk Management

2025 State of Machine Identity Security Report