[Updated] Beware--A Pop-up Window Phishing Flaw Affects Apple's Safari

and other web browsers according to this CNet article posted late yesterday. CNet wrote:

The issue...could allow a malicious Web site to refer visitors to a legitimate site--such as a bank's Web site--and then control the content displayed in a pop-up windows. The issue affects Microsoft's Internet Explorer, the Mozilla Foundation's Mozilla and Firefox browsers, Opera's browser, the open-source Konqueror browser and Apple Computer's Safari....

The exploit has been documented for Safari and confirmed with v1.2.4 by Secunia on this web page. The exploit with other browsers also have been documented by Secunia. Here is Secunia's demo of the vulnerability. [Update: Numerous readers reported that the demo vulnerability in Safari is eliminated if you check "Block Pop-Up Windows" (Apple-K) under the Safari menu. We have confirmed this. ed.] [Dana Baggett]


Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive