Java Vulnerability on Mac OS X

Word is spreading that there’s a critical security vulnerability in Java on Mac OS X. Actually, it’s a couple of vulnerabilities that can be taken advantage of to run commands outside of the browser as the user that launched the browser. The truth is that it’s been known about since at least August of last year and Sun, the makers of Java, fixed it long ago, but those fixes haven’t made it into Mac OS X yet, not even the 10.5.7 update.

So, what’s a Mac User to do? There’s no known use of exploit beyond the proof-of-concept examples, but the triage is pretty simple:

1. Turn off ‘Open “safe” files after downloading’ in Safari -> Preferences -> General
2. Turn off Java in Safari -> Preferences -> Security and any other browsers you use

This will prevent malicious Java code on a web page or downloaded from running automatically. There’s no reason to panic and JavaScript will still function normally, but it’s better to be on the safe side if you’re not regularly visiting web sites requiring Java.

If you’re technically inclined, you may be interested in the detailed explanation of the vulnerabilities.

[Via Daring Fireball]

Similar Posts

  • Play More Video Formats…

    I’m sure everybody has happened across a video file that they couldn’t play on their Mac because it was just unsupported. In the…

  • MacBreak – New Episodes

    In issue #316 of TechTails I mentioned a video podcast called MacBreak. Since then Leo and gang have put out a couple new…

  • Powerbooks that Boot Into Sleep Mode

    By Jon@Smalldog.com In this past week, I have come across three Powerbooks that constantly BOOT into sleep mode. Regardless of OS install, these…

  • Flash Player 10.2 – The Fastest Plugin Alive!

    Adobe yesterday released an updated version of Flash Player 10, featuring the highly anticipated ‘Stage Video’ hardware acceleration. As the controversy surrounding the…

  • AT&T Networks Down Across New England

    As I experienced firsthand this morning, AT&T is reporting a “massive outage” of their 3G and 4G networks in New England. Customers in…