Member Michael Lehn today reported the discovery of a security flaw in the Open "safe" files after downloading feature of Safari, also being reported by heise online. The flaw has been independantly confirmed.

When the Open "safe" files option is checked in the General tab of Safari preferences, a downloaded archive (zip file) containing a shell script named with a .jpg or .mov extension and missing the standard #!/bin/bash line can cause Safari to execute the shell script in the Terminal application without a confirmation prompt. A shell script has the privileges of the logged-in user, so in theory if a malicious script was executed this way, home folder files would be suspectible to damage. If the user was an administrator, system files and applications could be affected as well.

Two preventative measures can be used to avoid the flaw: (1) Disabling the Open "safe" files after downloading feature in Safari preferences. (2) Moving the Terminal application out of its normal location in the Applications/Utilities folder. The former method may be inconvenient during other routine downloads, while the latter may need to be reversed while performing Mac OS X updates.

The problem does not apply to other commonly used web browsers.

So far, a demonstration (proof of concept) download has been created, but no real exploits are known to exist. The problem has been reported to Apple Computer.

[Update] CNET reports that Apple is developing a patch for this security flaw, quoting an Apple representative as saying "We're working on a fix so that this doesn't become something that could affect customers" but without giving a delivery date for an update. Because the problem can reportedly affect Mail as well as Safari, the update may come in the form of changes to Mac OS X, not to Safari alone.

Popular Stories

iPhone SE 4 Thumb 1

New iPhone SE and iPad 11 Launch Timing Allegedly Revealed by Leaker

Tuesday January 7, 2025 11:12 am PST by
A new iPhone SE and an iPad 11 might be coming very soon. In late December, a private account on X with a track record of leaking accurate iOS-related information said devices codenamed "V59" and "J481" will be released alongside iOS 18.3 and iPadOS 18.3. Bloomberg's Mark Gurman has previously reported that "V59" is a new iPhone SE, and that "J481" is a new entry-level iPad. iOS 15.3, iOS ...
Generic iOS 18

Here's What's New in iOS 18.3 So Far

Friday January 3, 2025 11:58 am PST by
iOS 18.3 is currently in beta for developers and public beta testers. So far, the upcoming iPhone software update is very minor in scope. Below, we outline what is new in iOS 18.3 so far. The only potential new feature coming to iPhones with iOS 18.3 so far is robot vacuum support in the Home app, but this functionality is not yet live. Apple is laying the groundwork for the feature,...
iOS 18

Apple Releases iOS 18.2.1 With Bug Fixes

Monday January 6, 2025 10:07 am PST by
Apple today released iOS 18.2.1 and iPadOS 18.2.1, minor updates to the iOS 18 and iPadOS 18 operating systems. iOS 18.2.1 and iPadOS 18.2.1 come almost a month after Apple released iOS 18.2 and iPadOS 18.2. The new software can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update. According to Apple's release notes, iOS 18.2.1...
iPhone 17 Pro Dual Tone Rectangle Slimmer Feature 1

iPhone 17 Said to Feature More Seamless Camera Bump Design

Monday January 6, 2025 2:56 am PST by
The design of this year's next-generation iPhone 17 will allegedly feature a smoother transition between the edges of the device and the back cover, owing to Apple's use of a new glass-and-metal splicing material process. That's according to the Weibo-based leaker Fixed Focus Digital. In a post on Monday, the Chinese leaker claimed that suppliers say the iPhone 17 is adopting a "process...
apple vision pro

Apple Vision Pro May Now Be Out of Production

Tuesday December 31, 2024 2:00 pm PST by
Apple's first-generation Vision Pro headset may have now ceased production, following reports of reduced demand and production cuts earlier in the year. In October, The Information's Wayne Ma reported that Apple had abruptly reduced production of the Vision Pro headset ahead of potential plans to stop making the current version of the device completely by the end of 2024. With the year now...
LG UltraFine 6K Display TB5

LG Unveils UltraFine 6K Display With Thunderbolt 5 Support

Tuesday January 7, 2025 3:56 am PST by
LG has shown off a new Ultrafine 6K monitor at CES 2025. The 32-inch display is the first of its kind to support Thunderbolt 5, which Apple introduced late last year with the launch of new Mac mini and MacBook Pro models powered by M4 Pro chips. Details are scant, but we do know that the LG UltraFine 6K monitor (model 32U990A) features a Nano IPS Black panel, delivering a wide color gamut...
iOS 18 on iPhone Arrow Down

What to Expect From iOS 18.2.1, iOS 18.3, and iOS 18.4

Monday January 6, 2025 6:46 am PST by
Apple plans to release at least three iOS versions before the end of April, including iOS 18.2.1, iOS 18.3, and iOS 18.4. Below, we outline what to expect from each of these updates. iOS 18.2.1 Update: Apple has released iOS 18.2.1 with "important bug fixes." Last month, we reported that Apple has been internally testing iOS 18.2.1, which is expected to have a build number of 22C161....