📜 ⬆️ ⬇️

Vulnerability of personal data in Safari


On July 21, a vulnerability was discovered in Safari versions 4 and 5 that lay on the surface all the time, allowing an attacker to gain access to the contents of the address book.
In this regard, it is recommended to disable the use when auto-completing the contents of the address book.


As for the use, it is quite obvious: an attacker creates a site with the fields First Name, Last Name, and so on, in which the initial letters are searched using the script. Demonstration: ha.ckers.org/weird/safari_autofill.html

I know who your name is, where you work, and live (Safari v4 & v5)
Whoa! Disable your Safari AutoFill Immediately

')

Source: https://habr.com/ru/post/99903/


All Articles