Apple has updated its Safari browser to version 5.1 in a major upgrade that patches over 58 flaws. Several new features have also been added to the browser, including 'sandboxing'. Safari version 5.1 comes pre-bundled with Apple’s new operating system, OS X 10.7 or ‘Lion’, which was also released yesterday.
In all, 58 flaws were patched of which,
Requires Membership to View
To gain access to this and all member only content, please provide the following information:
By submitting your registration information to searchSecurity.in you agree to receive email communications from the TechTarget network of sites, and/or third party content providers that have relationships with TechTarget, based on your topic interests and activity, including updates on new content, event notifications, new site launches and market research surveys. Please verify all information and selections above. You may unsubscribe at any time from one or more of the services you have selected by editing your profile, unsubscribing via email or by contacting us here
- Your use of searchSecurity.in is governed by our Terms of Use
- We designed our Privacy Policy to provide you with important disclosures about how we collect and use your registration and other information. We encourage you to read the Privacy Policy, and to use it to help make informed decisions.
- If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States.
According to this support article, The update also patches bugs that could lead to disclosure of information and XSS vulnerabilities. Apple has refrained from disclosing or discussing the details of the vulnerabilities to prevent them being exploited before users have had a chance to upgrade to the latest versions.
WebKit, the open source browser engine that lies at Safari’s core was the component receiving most of the fixes. Apple cited ‘memory corruption issues’ in WebKit which may lead to ‘arbitrary code execution’ by merely visiting a maliciously crafted website.
In addition to the fixes, several new features have been added to Safari which includes ‘Reading list’, a feature that eliminates web ads from content saved for offline browsing. Safari 5 also boasts features which are available only on OS X Lion like multi-touch support, full-screen browsing and sandboxing.
The sandboxing feature will help thwart ‘drive-by’ attacks since any code executed within the browser will now be insulated from the rest of the operating system and application environment. This is the same mechanism used by Google’s Chrome browser, which also uses the WebKit engine.
Safari 5.1 runs on OS X 10.7 ‘Lion’ and OS X 10.6 ‘Snow Leopard’. Users of previous versions of OS X, OS X 10.5 or ‘Leopard’ must download Safari version 5.0.6. This is the second major update to Safari this year — the last being in March when over 60 bugs were patched.
Safari is available for download on the Apple website and also through Apple’s software update feature on both Windows and OS X, for existing users of Safari. More information on the update is available in this knowledgebase article.