Apple launches Safari 5, patches record 48 bugs
Fixes flaw in browser that hacker team exploited at Pwn2Own to win $15,000
Computerworld - Apple on Monday shipped the latest version of its Safari browser, patching a record 48 vulnerabilities, including one that a pair of hackers exploited in March to win a $15,000 prize.
The new browser debuted the same day as Apple unveiled the iPhone 4 at its annual Worldwide Developers Conference.
Safari 5, the first major upgrade to the Mac OS X and Windows browser in a year, fixed four dozen flaws, most of them in WebKit, the open-source engine that powers not only Apple's browser but also Google's Chrome. Apple also updated the previous edition to version 4.1 on Monday.
Among the 48 vulnerabilities was the one used by the two-man team of Vincenzo Iozzo and Ralf-Philipp Weinmann to hack an Apple iPhone 3GS in five minutes at the Pwn2Own contest last March, said Aaron Portnoy, security research team lead with HP TippingPoint. TippingPoint's 's Zero Day Initiative (ZDI) bug-bounty program paid the two researcher $15,000 -- a record amount for the four-year-old Pwn2Own -- for the Safari bug and exploit they used to break into the iPhone.
The Iozzo/Weinmann vulnerability was in WebKit, which is also the foundation of the stripped-down Safari browser Apple builds into the iPhone, iPod Touch and iPad.
Although Apple patched the bug in Safari 5 and 4.1 for Mac and Windows this week, it has not yet addressed the issue in its mobile devices. Presumably, Apple will do that with iOS4, the operating system upgrade slated to launch for the iPhone and iPod Touch June 21, and later this year for the iPad.
Portnoy said he was sure Apple would patch the vulnerability in the iPhone -- after all, that's where Iozzo and Weinmann exploited it for their Pwn2Own victory -- but admitted he had no idea when it would do so. "Apple is pretty secretive," said Portnoy.
Apple also dealt with a Windows-only bug that Polish researcher Krystian Kloskowski revealed a month ago. That vulnerability could be exploited by attackers simply by tricking users into visiting a malicious Web site.
Apple's advisory labeled 27 of the 48 vulnerabilities, or 56% of the total, with the company's "arbitrary code execution" phrase, meaning the flaws are critical and could be exploited to compromise a Mac or a Windows machine. Unlike other vendors, notably Microsoft, Apple does not rank the bugs it discloses. Seven of the bugs were cross-site scripting vulnerabilities that could be used by identity thieves.
Because Google's Chrome also relies on WebKit -- and like Safari is available on both the Mac and Windows -- it shouldn't come as a surprise that a number of the bugs fixed in Safari 5 and 4.1 were discovered by security engineers at Apple's rival. Google received credit for 25% of the vulnerabilities, double the percentage when Apple last patched Safari, in mid-March.
WWDC claim exposed: Apple Safari 5 isn't fastest
By comparison, Apple was credited with finding with only four flaws, or 8% of the total.
Safari is currently the world's No. 4 browser, accounting for a 4.8% share of the global browser usage market last month. The bulk of Safari usage is on the Mac; just 0.3 percentage point of Safari's total share came from the Windows version in May.
Safari 5 can be downloaded from Apple's site for Mac OS X 10.5 (Leopard), Mac OS X 10.6 (Snow Leopard), Windows XP, Windows Vista and Windows 7. Mac OS X users will be notified of the new version automatically by the operating system's software update feature, while Windows users already running Safari will be alerted by the Apple Software Update tool.
Apple also released Safari 4.1 for Mac OS X 10.4 (Tiger).
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, or subscribe to Gregg's RSS feed . His e-mail address is email@example.com.
- 5 reasons to upgrade to Apple's Safari 5
- Apple launches Safari 5, patches record 48 bugs
- iPhone 4, iOS 4 offer deeper enterprise support
- Apple's iPhone 4 is a pentaband phone
- Hands on with Apple's new iPhone 4
- AT&T's account site crumbles under iPhone owner load
- 'One more thing' ... iPhone 4 gets FaceTime video chat
- Image gallery: iPhone 4 up close
- Apple unveils iPhone 4, touts 'FaceTime' video chat
- What to expect from Apple and Steve Jobs at WWDC
Read more about Desktop Apps in Computerworld's Desktop Apps Topic Center.
- The Business Value of Continuous Delivery Download this whitepaper to learn more about the business value of Continuous Delivery and see why it could be a game changer for...
- Ten Factors Shaping the Future of Application Delivery Download this research report conducted by Enterprise Management Associates (EMA) to learn how those that are seeking to accelerate application delivery are leveraging...
- HTTP Status Code Cheat Sheet Look at the Graph, Find the Code and Boom - You're Solving Problems. Identifying and understanding common HTTP status codes can go a...
- Architects lead the next generation of data-driven applications Read this whitepaper to find out how application architects can quickly and confidently deliver long-lasting applications that minimize cost, complexity, and risk while...
- NSS Labs & Cisco Present: Evaluating Leading Breach Detection Systems Today's constantly evolving advanced malware and APTs can evade point-in-time defenses to penetrate networks. Security professionals must evolve their strategy in lockstep to...
- Will the Real Endpoint Threat Detection and Response Please Stand Up? This webinar explores new technologies & process for protecting endpoints from advanced attackers as well as the innovations that are pushing the envelope... All Desktop Apps White Papers | Webcasts