Mac's Safari Browser A Security Risk

Updated Niki_Fears 0 Tallied Votes 878 Views Share

Security researchers have been looking at Safari, the standard browser for Apple's Mac computers, and have found a troublesome security problem. It seems that there is a feature that could reveal your personal information. The problem is with the Auto Fill feature which is designed as a part of the Safari browser to help save you time and trouble when filling out various forms by storing the data on your computer then automatically filling out the information every time you come to that field in a form.

The problem, according to security experts, is with a vulnerability in the browser that could allow hackers to easily access your personal information which could put your privacy, your identity, and possibly other important information at risk. The data that is most at risk include your full name, your complete address including city and state, place of employment, and your email address. All of this information is stored by the Auto Fill feature in the operating system's local address book. Other standard text fields could also potentially be at risk.

Details about the potential security breech was outlined in a recent blog post from founder and CTO of White Hat Security, Jeremiah Grossman . A colleague of his, Robert “Rsnake” Hansen, who often collaborates on security issues of this sort has actually worked out a to demonstrate how easily a malicious web site could use fairly simple code to obtain this information without your knowledge and in ways that most security software could never pick up on. While it appears that fields containing only numbers, such as your telephone number, are not as vulnerable, the security implications and possible abuses are still enormous.

The quick fix solution to this problem, is of course, simply not to use the Auto Fill feature when using Safari.

Grossman says that he had notified Apple officials of the security problem before going public with the information. He states that he sent notification on June 17th and as of the posting of his blog on Wednesday, July 21st, he has yet to hear anything from Apple on this matter..

Dani AI

Generated

Echoing : Safari's AutoFill could be abused to pull data from the local Contacts/"My Card" without explicit user consent. Apple assigned the issue CVE-2010-1796 and released Safari updates (Safari 5.0.1 / 4.1.1) to address the problem — install those updates if you have not already. (Apple Support) (MacRumors summary of the update). Independent coverage at the time explains what fields were at risk (name, company, city/state/country, email) and how a malicious page could trigger AutoFill. (Macworld explainer).

Immediate steps to protect an unpatched system or to avoid the feature altogether:

  1. Open Safari -> Preferences (Command+,) -> AutoFill.
  2. Uncheck the option that uses contact/address-card info (labels vary by version: "Using info from my contacts" / "Autofill web forms using info from my Address Book card").
  3. Leave other AutoFill options off or tune them individually (passwords, credit cards, forms) as you prefer.
    See Apple’s AutoFill guidance for exact menu labels for your macOS version. (Change AutoFill settings in Safari).

Additional mitigations: update Safari via Software Update; consider removing or minimizing sensitive fields on your Contacts "My Card" or choose a different card as My Card if you must keep AutoFill enabled; and prefer a dedicated password manager for credentials instead of broadly enabling form AutoFill. Guidance on the Contacts "My Card" is here. (Set up your My Card in Contacts). Note: a follow-up variant was reported later in 2010 that required minimal user interaction, so disabling AutoFill until you install the official update is the safest short-term move. (MacRumors follow-up).

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.