HomeSecuritySafari browser: Bug revealed because Apple delayed the patch

Safari browser: Bug revealed because Apple delayed patch

Safari browser

A security researcher has published details about a bug in browser Apple's that could be exploited by malicious hackers to steal or leak files from users.

The bug was discovered by Pawel Wylecial, co-founder of Polish security REDTEAM.PL.

Wylecial reported the bug to Apple in the spring, specifically in April, but the researcher decided to make his findings public now, since the OS manufacturer has delayed fixing the bug and is scheduling it for spring 2021, a year later.

How does the Safari browser bug work?

In a blogpost, Wylecial said the bug lies in the Web Share API Safari browser's - a new web standard that introduced a cross-browser API that allows sharing of text, links, files and other content.

The security researcher says that Safari (on iOS and macOS) supports sharing files stored on the user (via the file:// URI scheme).

This is a significant security issue, as it could lead to situations where malicious pages might invite users to share an article via email, but end up exposing files from their device.

In the video below, you can see how the bug works:

However, Wylecial described the bug as “not very serious” as it required user interaction and social engineering to trick users into exposing local files. However, he admitted that it was also very easy for attackers to “make the exposed file invisible to the user.”

Apple bug
Criticism of Apple for the way it handles patches

However, the real issue here isn't just the bug itself in the Safari browser and how easy or difficult it is to use. It's how Apple handled the bug report.

Apple failed to prepare a patch in a timely manner (it’s been over four months). Furthermore, it tried to delay the researcher from publishing his findings until next spring, almost a full year after the bug was initially reported and beyond the 90-day “Vulnerability Disclosure Deadline.”

Situations like this one that Wylecial had to face are becoming increasingly common among iOS and macOS bug hunters.

Apple – despite announcing a bug bounty program – is increasingly being accused of delaying bug fixes and trying to convince researchers not to make their findings public.

For example, when Wylecial revealed the Safari browser bug today, other researchers reported similar situations where Apple was slow to fix security.

When Apple announced the rules for its Security Research Device program in July, Google 's Project Zero security team refused to participate, claiming that the program's rules were specifically written to limit public disclosure.

Three months ago, in April, another security researcher reported, also, a similar experience with Apple's bug bounty program, which he described as “funny”, saying that the program's goal is “to keep researchers' mouths shut for as long as possible”.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS