Subscribe via feed.

Apple Safari WebKit Scroll Event Handling Remote Use-After-Free

Posted by deepcore under Apple, exploit, OSX security tools (No Respond)

The VUPEN Vulnerability Research Team discovered a critical vulnerability in Apple Safari. The vulnerability is caused by a use-after-free error in the WebKit library when handling certain scroll events, which could be exploited by remote attackers to compromise a vulnerable system by tricking a user into visiting a specially crafted web page. Versions 5.0.3 and below are affected.

Tags: , ,