Apple to patch Safari before Pwn2Own, say researchers
Clues point to impending update that will beef up browser before next week's hacking contest
Computerworld - Apple will patch its Safari browser before the Pwn2Own hacking contest kicks off next week, security researchers hinted today.
If accurate, Apple will join both Google and Mozilla, which earlier this week issued security updates for Chrome and Firefox as preparation for Pwn2Own.
On Wednesday, Apple patched a record 57 vulnerabilities in its iTunes music software; 50 of those bugs were attributed to WebKit, the open-source browser engine that Safari's built on. iTunes relies on WebKit to render its online store component.
"Anti-pwn2own again: Apple fixed a record of 50 vuln[erabilities] in WebKit (iTunes), and is preparing the update for Safari/Mac OS X," said French security firm Vupen in a message on its Twitter account.
Vupen's mention of Pwn2Own refers to the annual hacking contest held at the CanSecWest security conference in Vancouver, British Columbia. This year's Pwn2Own runs March 9-11.
At Pwn2Own, security researchers will compete for $65,000 in prizes by trying to take down the most up-to-date editions of Safari 5, Google's Chrome 9, Microsoft's Internet Explorer 8 and Mozilla's Firefox 3.6.
It's not unusual for Apple to patch WebKit flaws in one application before it rolls out those same fixes for another. In the past, however, it's usually patched WebKit vulnerabilities in Safari before addressing them in iTunes.
Other clues to an upcoming Safari update came from HP TippingPoint -- coincidentally the sponsor of Pwn2Own -- which issued advisories on two WebKit bugs patched in iTunes yesterday. The bugs were originally reported to TippingPoint's Zero Day Initiative (ZDI) bug bounty program; ZDI passed the reports to Apple last October.
Both the advisories said that attackers could exploit the bugs to "execute arbitrary code on vulnerable installations of Apple ... WebKit" and that the vulnerabilities could be triggered using "drive-by" tactics that only require a victim to visit a malicious Web site.
Another hint that Safari will be patched soon came from the iTunes advisory posted by Apple on Wednesday. None of the 50 WebKit bugs listed in the advisory were accompanied by the usual terse Apple description; instead, Apple only noted the CVE (Common Vulnerabilities and Exposures) identifying number and the researcher(s) who first reported the flaw.
More than 30 of the 50 WebKit vulnerabilities were credited to Google researchers and developers. Google's Chrome, like Safari, is built on the WebKit engine.
If Apple patches Safari, it will be the third browser to update this week.
Google patched 19 bugs in Chrome on Monday, and Mozilla followed that on Tuesday with an 11-patch update to Firefox.
Last year, only Apple and Google updated their browsers just before Pwn2Own. Mozilla acknowledged a critical vulnerability in Firefox less than a week before 2010's contest, but said it wouldn't fix the flaw in time for the challenge. Pwn2Own organizers later ruled that Firefox vulnerability off limit.
Assuming Apple updates Safari, of the four Pwn2Own-targeted browsers, only Internet Explorer (IE) will remain unpatched in the days leading up to the contest. Microsoft last issued fixes for IE flaws on Feb. 8 as part of its monthly Patch Tuesday.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@computerworld.com.
Pwn2Own 2011
- iPhone, BlackBerry tumble to Pwn2Own hackers
- Researcher chains three exploits to take down IE8 at Pwn2Own
- Safari, IE hacked first at Pwn2Own
- Researcher blows $15K by reporting bug to Google
- Microsoft won't patch IE before Pwn2Own
- Apple to patch Safari before Pwn2Own, say researchers
- Mozilla follows Google, patches Firefox as prep for Pwn2Own
- Three-time Pwn2Own winner knocks hacking contest rules
- Familiar faces, new names step up at Pwn2Own hacking contest
- Update: Firefox update will patch CSRF bug, Mozilla says
Read more about Security in Computerworld's Security Topic Center.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Protection for Every Enterprise: How BlackBerry 10 Security Works Get an IT-level review of BlackBerry® 10 Security, addressing data leakage protection, certified encryption, containerization and much more.
- A Comprehensive Strategy to Leverage Mobile A successful mobile strategy begins with a common platform for integrating and managing mobile devices and the corporate assets that are stored on...
- IDC - SAP Enterprise Mobility: Bringing a Cohesive Approach to a Complex Market This IDC white paper discusses key mobility trends and examines how SAP's mobile enterprise solutions map to meet organization's mobile requirements.
- The App Happy Enterprise This Computerworld playbook explores key aspects of the enterprise mobile revolution and provides a set of step-by-step directions on how to productively manage...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
