Security Vulnerability in Apple's Safari RSS Reader

I use Apple’s Safari web browser almost every single day. I like it and I depend on it. Thus I was alarmed to read that Brian Mastenbrook recently discovered that Safari’s RSS reader is “vulnerable to an attack that allows a malicious web site to read files on a user’s hard drive without user intervention.”

Apparently this “can be used to gain access to sensitive information stored on the user’s computer, such as emails, passwords, or cookies that could be used to gain access to the user’s accounts on some web sites.”

Mastenbrook notes that this vulnerability has been acknowledged by Apple. It affects Safari in Leopard and in Windows, but apparently does not affect people using Tiger.

Originally it seemed that the solution was very simple: change your default RSS reader from Safari to another RSS application in Safari’s preferences. However, Mastenbrook’s further research showed that this does not completley disassociate Safari all RSS feeds.

To work around this issue until a fix is released by Apple, Mastenbrook suggests the following steps. Note that I was able to easily do this on all of my Macs.

1. Download and install the RCDefaultApp preference pane, which you can get by clicking here.

2. This installs into your Mac’s system preferences. Open your Mac’s system preferences by clicking on the Apple in the upper left corner of your Mac’s screen and choosing “System Preferences”.

3. Click on the the Default Applications option.

4. Select the “URLs” tab at the top of the window that opens. Now choose the “feed” URL type from the column on the left, and choose a different application (such as NetNewsWire or NewsFire which is my prefered desktop RSS app. You can also choose Mail in Leopard, which has an RSS reader and is not affected by the issue.).

5. Repeat the previous step for the “feeds” and “feedsearch” URL types. Note that you don’t need to set a different app for these options; I chose the ““ option here.

I’ve performed the above steps with no difference in performance for Safari. I’m sure Apple is working on a patch to be released ASAP.

Read the original report by clicking here.

It’s extremely unlikely that a Safari user would be affected by this. However, it’s almost always better to be safe than sorry. Thank you to Brian Mastenbrook for discovering this issue!

Similar Posts

  • Here They Are! The Beatles!

    Apple today announced the availability of the entire Beatles catalog in the iTunes Music Store. After years of back and forth negotiations with…

  • iPhone Web Applications Portal

    Just yesterday Apple opened up a new web site dedicated to showcasing web applications made specifically for the iPhone. Currently their portal is…

  • A Look at the iPhone Family

    Image Credit: MacRumors Apple today announced the addition of the iPhone 4S to the iPhone family, as well as a new price point…

  • Vermont Ranked #1 Mac State

    According to recent research conducted by Chitika, Vermont is the top Mac-using state in the US. With 19.55% of the population reportedly using…

  • Cingular is now AT&T

    Ok, so Cingular has the exclusive contract on the iPhone, right? Well, sort of – because “Cingular” is now AT&T. In other words,…

  • Apple Releases Mac OS X 10.7 Lion

    On Wednesday, Apple released the highly anticipated Mac OS X 10.7 Lion via the Mac App Store. The eighth major release of OS X, Lion marks the first version of the world’s most advanced operating system available exclusively through the Mac App Store. Bypassing the traditional CD/DVD format of past releases, Mac OS X Lion is a significant step forward both in terms of its new features and in how operating systems are acquired and installed.

    Introducing over 250 new features, Lion is an enticing upgrade—especially given its very affordable $29.99 price point. The scale of Wednesday’s release is in line with the shift from Mac OS X 10.4 Tiger to Mac OS X 10.5 Leopard in the fall of 2007. While Mac OS X 10.6 Snow Leopard acted as a bridge between Leopard and Lion, it was more of a refinement of the features already introduced in 10.5. Given this, Mac users have been waiting patiently for nearly four years for an upgrade of Lion’s scale, and thankfully it doesn’t disappoint.

    Lion includes many groundbreaking new features including: enhanced Multi-Touch gestures, support for full screen apps, Mission Control, Launchpad, the Mac App Store and a completely redesigned version of Mail. As mentioned during keynotes and media events throughout its development, many of these new features are directly inspired by, or even copies of, features of Apple’s iOS mobile operating system. Due to this amalgamation, Lion has been toted as a synthesis of the best aspects of Mac OS X and iOS.

    Almost as amazing as its new features is the way Lion is acquired and installed. No longer is a trip to the store to purchase a boxed version of the OS required. Users running Mac OS X 10.6.8 with compatible Intel Macs can download Lion from the convenience of their homes and offices through the Mac App Store. What many are already referring to as the simplest install of OS X ever, Lion can be installed and configured with just a few clicks. Phil Schiller, Apple’s senior vice president of Worldwide Product Marketing contributed the following on Lion’s release and the ease of its install:

    “Lion is the best version of OS X yet, and we’re thrilled that users around the world can download it starting today. Lion makes upgrading a Mac easier than ever before; just launch the Mac App Store, buy Lion with your iTunes account, and the download and install process will begin automatically.”

    Supplementing the aforementioned features, Lion includes a series of refinements which look to radically change the way OS X is experienced and used. Among these Resume, Auto Save and Versions effectively eliminate the need to save files as they automatically preserve your Mac’s state prior to a restart or shutdown, continuously save your documents in the background and even keep a running history your of files as you work. Lion also introduces AirDrop, which revolutionizes file transfers to nearby Macs, making Sneakernet flash drive exchanges a thing of the past.

    Mac OS X 10.7 Lion is now available on the Mac App Store, and retails for $29.99. To ensure your Mac is compatible and ready to upgrade, click here.

    To purchase Lion, click here. (opens the Mac App Store)

    System Requirements:

    • Intel-based Mac with a Core 2 Duo, i3, 15, i7 or Xeon processor
    • Mac OS X 10.6.8 Snow Leopard
    • 2GB of RAM
    • 4GB available hard drive space