A security researcher has discovered a vulnerability in Apple Safari Web browser that allows web sites to collect personal information on visitors. The flaw, which operates the Web browser auto-fill “capability allows Web sites to scrape information such as name, email, address, telephone number and place of work the person using the equipment that many Macintosh users to store their digital address books.
The error in Safari, Apple has acknowledged, is the latest to highlight the difficulties that Apple and other technology companies face in relation to personal data falling into the wrong hands. Last month, an error in one of AT & T Web site lists the e-mails of 114,000 IPAD owners. This month, an iPhone developer violated the iTunes user accounts to make several unauthorized purchases.

Safari Browser Apple
In a statement, Apple has acknowledged the latest ruling in Safari, but gave no further details. “We take security and privacy very seriously,” the company said. “We are aware and working on a solution.”
The researcher who discovered the flaw, Jeremiah Grossman, chief technology officer of security firm WhiteHat Security, said he chose to post information on his blog after Apple reported the problem in June Grossman said he received an automated response from Apple through e-mail, but the company never followed.
In an interview, Mr. Grossman said the Deputy long is easy to exploit. As a result, said he suspected that the site can be used to collect personal information from unsuspecting visitors.
“It’s very easy to do,” he said. “We can only assume that other people have used.”
Grossman said he discovered the bug doing research on browser vulnerabilities intends to present at a security conference in Las Vegas next week. At that time, said he also will present the most damaging insects that affect versions of Microsoft Internet Explorer, the most widely used Web browser. Grossman said that Safari is currently used by 83 million people.
While the iPhone and the IPAD use the Safari web browser, Mr. Grossman said the ruling will not affect the versions of Safari running on these devices.
Some Web sites recommend that users disable the auto-fill the capacity until the error is corrected.

Posted in
Tags:
