SecureMac, Inc.

Apple Safari Vulnerability

June 9, 2009

Security Alert: Safari prior to version 4 (released June 8th, 2009) may permit malicious web pages to steal files from the local system simply by accessing a web page without further interaction. This vulnerability is present in both Mac OS X and Windows Safari. The attack is accomplished by mounting an XXE attack against the parsing of the XSL XML.

Apple Safari Vulnerability

XXE attack – Local File Theft Vulnerability

Posted: June 9th, 2009
Updated: June 15th, 2009

Security Risk: Moderate

UPDATE: Today Apple released Java for Mac OS X 10.5 Update 4, which is an update that appears to correct the Java vulnerability reported by SecureMac last month. The update requires OS X 10.5.7 or higher. More information can be found at: http://support.apple.com/kb/HT3581.

Safari prior to version 4 (released June 8th, 2009) may permit malicious web pages to steal files from the local system simply by accessing a web page without further interaction. This vulnerability is present in both Mac OS X and Windows Safari. The attack is accomplished by mounting an XXE attack against the parsing of the XSL XML.

Chris Evans has documented this vulnerability in his advisory on his website http://scary.beasts.org/security/CESA-2009-006.html

Safari 4 is now available for download for both Windows and Macintosh systems. Suggested to upgrade or to use an alternative browser such as Firefox.

Get the latest security news and deals