Safari

Apple declines to fix vulnerability in Safari's Web Archive files, likely because it requires user action to exploit

Apple declines to fix vulnerability in Safari's Web Archive files, likely because it requires user action to exploit

Metasploit software developer Joe Vennix has detailed a vulnerability in Safari’s webarchive file format along with how it can be exploited. The post on Rapid7 indicates that after being reported to Apple back in February, the bug was closed last month with a status of “wontfix”, indicating that Apple has no plans to address the bug. So what is it and why is that?

Nick Arnott 2