Tech

This worrying Apple Safari security bug could leave users wide open to cyberattacks

Share
Share


  • SquareX says hackers can abuse the Fullscreen API in Safari to trick people into running remote browsers
  • The browser-in-the-middle attack is good for stealing login credentials
  • Apple says guardrails are in place and will not pursue it further

Fullscreen API, a functionality in the Apple Safari browser which allows web developers to present specific elements in fullscreen mode, has a vulnerability that is being abused in convincing password theft attacks, experts have warned.

Security researchers SquareX claim to have observed an increase in use in this type of attack, which leverages the browser-in-the-middle (Bitm) technique.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
E-bikes and e-scooters are popular—but dangerous. A transport expert explains how to make them safer
Tech

E-bikes and e-scooters are popular—but dangerous. A transport expert explains how to make them safer

Credit: Unsplash/CC0 Public Domain Last weekend a pedestrian in Perth tragically died...

Expand your Mac mini M4 with this sleek dock offering ports, cooling and up to 16TB storage
Tech

Expand your Mac mini M4 with this sleek dock offering ports, cooling and up to 16TB storage

Beelink Mate adds ports and storage without changing your Mac mini’s footprint...