This worrying Apple Safari security bug could leave users wide open to cyberattacks




  • SquareX says hackers can abuse the Fullscreen API in Safari to trick people into running remote browsers
  • The browser-in-the-middle attack is good for stealing login credentials
  • Apple says guardrails are in place and will not pursue it further

Fullscreen API, a functionality in the Apple Safari browser which allows web developers to present specific elements in fullscreen mode, has a vulnerability that is being abused in convincing password theft attacks, experts have warned.

Security researchers SquareX claim to have observed an increase in use in this type of attack, which leverages the browser-in-the-middle (Bitm) technique.

https://cdn.mos.cms.futurecdn.net/TKhrBSejFRYhxHvjGVYnDn.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img