New Paranoid Android v1.3 "Fixes" Safari Automatic Script Execution Vulnerability and More

We noted yesterday that Secunia.com had reported a new vulnerability in Safari and recommeded that be unchecked in Safari's General preference panel. Paranoid Android v1.3 is free from Unsanity and it fixes the automatic portion of the Safari (and Mail) vulnerability and the general issue with LaunchServices in Mac OS X 10.4.x "Tiger" of which the new vulnerability is a subset. According to Unsanity, here's what's new in version 1.3:

  • Paranoid Android can now notify you when a file is launched with a custom application (one other than the default one for the document's file type). This does not affect opening documents from within applications.
  • Updated to mitigate the recent Safari/LaunchServices exploit described in detail here.

We used Paranoid Android previously after a vulnerability in Widget downloading and installation was discovered and until Apple closed it. We downloaded and installed v1.3 (and v1.5.1 of Unsanity's APE which is required), logged in and out and then tested it on Secunia's demo page. Paranoid Android 1.3 prevented the demo exploit by intercepting the command to open the Terminal.app and asking us if we really expected and wanted that to happen--we clicked "Cancel." [Bill Fox]



Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Mac OS · This month in the archive