Safari Security Flaw Reported [Updated] - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Safari Security Flaw Reported [Updated]

by

Member Michael Lehn today reported the discovery of a security flaw in the Open "safe" files after downloading feature of Safari, also being reported by heise online. The flaw has been independantly confirmed.

When the Open "safe" files option is checked in the General tab of Safari preferences, a downloaded archive (zip file) containing a shell script named with a .jpg or .mov extension and missing the standard #!/bin/bash line can cause Safari to execute the shell script in the Terminal application without a confirmation prompt. A shell script has the privileges of the logged-in user, so in theory if a malicious script was executed this way, home folder files would be suspectible to damage. If the user was an administrator, system files and applications could be affected as well.

Two preventative measures can be used to avoid the flaw: (1) Disabling the Open "safe" files after downloading feature in Safari preferences. (2) Moving the Terminal application out of its normal location in the Applications/Utilities folder. The former method may be inconvenient during other routine downloads, while the latter may need to be reversed while performing Mac OS X updates.

The problem does not apply to other commonly used web browsers.

So far, a demonstration (proof of concept) download has been created, but no real exploits are known to exist. The problem has been reported to Apple Computer.

[Update] CNET reports that Apple is developing a patch for this security flaw, quoting an Apple representative as saying "We're working on a fix so that this doesn't become something that could affect customers" but without giving a delivery date for an update. Because the problem can reportedly affect Mail as well as Safari, the update may come in the form of changes to Mac OS X, not to Safari alone.

Popular Stories

HomePod mini and Apple TV Sage

New Apple TV and HomePod Mini Are 'Nearly Ready' to Launch, New Siri Remote Also Rumored

Sunday May 31, 2026 8:47 am PDT by
New models of the Apple TV 4K and HomePod mini are "nearly ready to go," according to the latest word from Bloomberg's Mark Gurman. Subscribe to the MacRumors YouTube channel for more videos. Both devices have been ready "for months," but Apple is holding off on launching them until the more personalized version of Siri is available, he said. "I am told the hardware for the next Apple TV...
iphone 17 pro black feature

iPhone 18 Pro's Camera Upgrade Will Cost Apple 50% More

Friday May 29, 2026 3:44 am PDT by
The iPhone 18 Pro and iPhone 18 Pro Max's all-new variable aperture lens will cost Apple 50% more than the camera unit used in current models, according to supply chain analyst Ming-Chi Kuo. Variable aperture has been one of the most persistent iPhone camera rumors of the past few years. Kuo first flagged the feature in late 2024, and it has since been corroborated by multiple reports and...
iphone 18 pro color dummies

First Look at iPhone 18 Pro Color Options Revealed by Dummy Models

Friday May 29, 2026 4:50 am PDT by
Leaker Sonny Dickson today shared images of iPhone 18 Pro dummy models in the device's four rumored colors, offering the first real-world look at what to expect from the lineup visually. Corroborating previous rumors, the dummies show the iPhone 18 Pro Max in Light Blue, Black, Silver, and Dark Cherry. Dickson said "Cherry will probably be the next hit, orange did very well." Cosmic Orange...

🔗 Related Apple News & Rumors

Stay updated with the latest Apple ecosystem news and verified rumors