Apple Fixes Safari Browser Flaws

Apple Fixes Safari Browser Flaws

Written By
Brian Prince
Brian Prince
Aug 12, 2009
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Apple has issued a new round of patches to cover critical issues in its Safari browser.

All totaled, Apple plugged six security holes. Three of them cover problems in the browser’s Webkit engine, which also powers Google Chrome. Arguably the most serious of the Webkit issues is a buffer overflow vulnerability in the engine’s parsing of floating point numbers. If a user visits a malicious Web page, an attacker can exploit the situation to execute code on the compromised system, Apple warned in the advisory.

In addition to the Webkit bugs, there is a fix for a flaw tied to the Top Sites feature Apple introduced in Safari 4.0. Designed to provide users with thumbnails of sites they frequently surf, the feature can be abused by attackers to lure users to rogue sites.

“This issue is addressed by preventing automated Website visits from affecting the Top Sites list,” Apple officials wrote in the advisory. “Only Websites that the user visits manually can be included in the Top Sites list.”

Two of the fixes – one affecting the CoreGraphics component, the other ImageIO – are specifically aimed at Windows XP and Vista. Both vulnerabilities can be exploited via malicious sites, Apple warned in its advisory.

“It doesn’t matter whether you run Safari on a Mac OS X or Windows computers, it’s important that you apply these security patches detailed in a security advisory on Apple’s Website,” blogged Graham Cluley, senior technology consultant at Sophos.

Safari 4.0.3 for Windows or Mac is available for download here.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.