Categories: SecurityWorkspace

Apple Fixes WebKit Vulnerability in Safari

Apple has issued a security update for its Safari web browser that fixes a WebKit vulnerability that could allow the execution of arbitrary code if a user visited a malicious website.

In its release notes for Safari versions 6.1.6 and 7.06, the company says the flaw was caused by “multiple memory compression issues” and has been resolved through improved memory handling.

Apple cites seven Common Vulnerabilities and Exposures IDs (CVE-IDs), five discovered by itself, one by Google’s Chrome Security team and another by an anonymous researcher. As well as executing code, the flaw also allows the termination of applications.

Apple Safari bug fixes

The update is available for Mac OS X Lion v10.7.5, OS X Lion Server v10.7.5, OS X Mountain Lion v10.8.5, OS X Mavericks v10.9.4.

In April, 27 bugs were fixed, many of which were also related to the WebKit browser engine that Safari uses. A number of these were also memory corruption flaws that could also have allowed attackers to gain access to people’s Mac OS X Machines.

Safari currently commands 5.16 percent of the desktop browser market, placing it in fourth position, behind Mozilla’s Firefox, Google Chrome and the various versions of Internet Explorer.

Mac OS X Yosemite is currently available as a beta, the first time a pre-release version has been made available to anyone other than developers. The final version is due to be released as a free update later this year via the Mac App Store.

Are you a security expert? Try our quiz!

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

Recent Posts

Silicon UK Unveils a Bold New Redesign

Discover Silicon UK's bold new redesign—enhancing tech journalism, user experience, and client campaigns with a…

2 days ago

Meta To Spend ‘Hundreds Of Billions’ On AI Data Centres

Meta vows to spend hundreds of billions of dollars on AI infrastructure as it seeks…

3 days ago

Pentagon Awards AI Contracts To OpenAI, Google, Anthropic, xAI

US Defence Department hands contracts of up to $200m each to AI leaders as White…

3 days ago

OpenAI Delays Open Source Model Indefinitely

OpenAI pushes back release of hotly anticipated open-source model indefinitely as it seeks to compete…

3 days ago

HSBC Sees $40bn Driverless Taxi Market In China

Driverless taxis could see $40bn in revenues a year in mainland China, boosted by cutting-edge…

3 days ago