Apple - Apple Issues Safari Security Update - eWeek Security Watch

Apple Issues Safari Security Update

Written By
Brian Prince
Brian Prince
Nov 18, 2010
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Apple fixed 27 vulnerabilities in Safari for Mac OS X and Windows today.

All of the vulnerabilities exist in the open-source Webkit engine. In addition, nearly all of them can be exploited to execute code remotely on Macs or Windows PCs.

Among the vulnerabilities is a problem due to Safari using a “predictable algorithm” to generate random numbers for JavaScript applications. This may allow a Website to track a particular Safari session without using cookies, hidden form elements, IP addresses or other techniques, Apple warned. The update addresses the issues by using a stronger random number generator.

Several of them can be exploited through drive-by attacks on malicious sites, Apple noted in the advisory. For example, an integer overflow exists in Webkit’s handling of Text objects, and could be exploited via a maliciously crafted Website to cause an application crash or permit code execution. The issue was fixed through improved bounds checking, Apple said.

More information about the update can be found here.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.