Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Mac OS X Safari Browser Exploit Discovered

Add as a preferred source on Google

A potentially severe security flaw has been uncovered in Apple‘s Safari Web browser, which may enable attackers to execute arbitrary Unix shell scripts on a user’s machine simply by following a link on a Web site.

The exploit involves the way Mac OS X determines which program it should launch when opening files of a particular type. By renaming a Unix shell script to an extension Safari considers “safe,” omitting the script’s so-called “shebang line” (a command which specifies how the script should be executed), and compressing the script with the Zip archiving utility, Safari can be convinced to download the script, decompress it, assume the script is “safe,” then pass it off to the Mac OS X Terminal application for execution. An attacker could easily use such a script to delete a user’s home directory, damage the computer’s configuration, or obtain personal data.

Recommended Videos

Apple has yet to comment or release a patch. In the meantime, Safari users should disable the “Open ‘safe’ files after downloading” option in General pane of Safari’s preferences. This option is disabled by default in new installations of Mac OS X 10.4.5, but may be enabled by default in older systems or systems which have been upgraded to Mac OS X 10.4.5.

So far, Safari is the only application known to be affected, although it is possible other programs could be vulnerable to similar attacks. The Camino and Firefox Web browsers are not vulnerable to this particular exploit.

Danish security firm Secunia has listed the flaw as “extremely critical,” and has posted a harmless sample exploit of the flaw so users can test if their systems are vulnerable. Heise Online has another demonstration of the exploit.

Users may also be able to protect themselves from the exploit by removing the Terminal application from its default location in Applications > Utilities. (However, doing so may confuse future system updaters, so users would probably have to remember to put it back before installing new software.)

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
One of the most capable desktop processors available just got $125 cheaper: AMD Ryzen 9 9950X3D down to $573
AMD Ryzen 9 9950X3D drops to $573.99 (18% off): 16-core, 144MB cache, AM5, 3D V-Cache.
AMD Ryzen 9 9950X3D deal

The AMD Ryzen 9 9950X3D is down to $573.99 in a limited-time deal, a $125 saving off its $699 list price, and it represents something AMD hadn't offered before: a 3D V-Cache processor with a high enough core count to handle demanding creative and professional workloads without sacrificing the gaming performance that cache stacking delivers. For anyone running one machine for everything, this is the processor the 9000 series has been building toward.

get the deal

Read more
Adobe Firefly AI is now live publicly, hoping you’ll talk to an AI and get work done
Firefly AI Assistant can to handle your entire creative workflow
adobe-firefly-ai-assitant-public-beta

Adobe just opened up the public beta for Firefly AI Assistant. It is a conversational AI agent that sits across your entire Creative Cloud suite and handles multi-step workflows on your behalf.

You just have to describe what you want, and the assistant will figure out which Adobe tools to use and in what order, including Photoshop, Lightroom, Premiere, Firefly, and others.

Read more
Meta’s latest outrageous deal is getting solar power beamed even at night from satellites
Meta's deal with Overview Energy isn't just about clean power. It's a preview of what keeping AI running sustainably at planetary scale is going to require.
Satellite by Starlink

Out of all the things Meta has ever been accused of, thinking small hasn’t been one of them. 

The company that owns the most popular social media and messaging platforms like Facebook, Instagram, Messenger, and WhatsApp, is now looking at beaming sunlight from space to the Earth’s surface for powering its AI data centers after dark (via TechCrunch). 

Read more