Apple has released an update to the beta of its Safari 3 browser for Windows that repairs three vulnerabilities.
Two of the repaired flaws could allow an attacker to take control of a system. A third exposes the user to a cross-site scripting vulnerability that could lead to disclosure of confidential information.
Security researchers took just hours to find the first security holes after Apple released a beta of the browser on Monday. Researchers have reported a total of seven security vulnerabilities.
One of the repaired vulnerabilities was discovered by Thor Larholm, although Apple did not credit the researcher.
"Given that Apple has a lousy track record with security on OS X, and a hostile attitude towards security researchers, a lot of people are expecting to see quite a number of vulnerabilities targeted at this new Windows browser," he wrote when he disclosed his vulnerability in a blog posting on Tuesday.
In another posting, Larholm claimed that the update is still ignoring several weak spots in the browser that allow him to crack the security again with a few tweaks to his original exploit.
Safari 3 is currently in beta making it unlikely that people are using the software as their primary browser. This will limit the risk that attackers will target the vulnerabilities.
Breaking with the way the company traditionally discloses security flaws, Apple did not post details of the update on its security updates site but disclosed them in an email to a mailing list.
Apple is breaking with common procedures in other areas too. The update to the application is listed as version 3.01, but it is uncommon to change version numbers of software when in the testing phase.
Apple plugs three Windows Safari holes
By
Tom Sanders
on Jun 18, 2007 7:02AM

Got a news tip for our journalists? Share it with us anonymously here.
Partner Content

Kaseya Dattocon APAC 2024 is Back

Secure, integrated platforms enable MSPs to focus bringing powerful solutions to customers

Channel can help lead customers to boosting workplace wellbeing with professional headsets

How NinjaOne Is Supporting The Channel As It Builds An Innovative Global Partner Program

Tech For Good program gives purpose and strong business outcomes
Sponsored Whitepapers
-1.jpg&w=100&c=1&s=0)
Stop Fraud Before It Starts: A Must-Read Guide for Safer Customer Communications

The Cybersecurity Playbook for Partners in Asia Pacific and Japan

Pulseway Essential Eight Framework

7 Best Practices For Implementing Human Risk Management

2025 State of Machine Identity Security Report