Old Apple Safari browsers retain easily accessible IDs and passwords

Safari
Watch out for vultures on your Safari

Kaspersky Labs has discovered a flaw in Apple's Safari browser that lists user IDs and passwords in plaintext, according to a blog post made on the company's Securelist website.

The problem appears to derive from Safari's retention of browser history in the 'Reopen All Windows from Last Session' feature, which lets users quickly revisit the sites that they had been browsing in a previous online session. Most browsers have this feature and, though convenient, it isn't entirely safe.

Kaspersky has found that the document Safari creates to allow the restoration to occur is in plaintext format. The plaintext also contains whatever IDs and passwords may have been in use during the previous Safari session. The file is hidden, but isn't hard to find for something who knows what they are looking for.

Mauled on Safari

As the post states: "You can just imagine what would happen if cybercriminals or a malicious program got access to the LastSession.plist file on a system where the user logs into Facebook, Twitter, LinkedIn or their online bank account." It then adds: "As far as we are concerned, storing unencrypted confidential information with unrestricted access is a major security risk."

The security company has pointed the problem out to Apple, and also says that it is not aware of any malware that might be targeting the flaw. The blog post has been online since Friday, however, so there can be no certainty that malware-writers have not noticed and begun their work.

Apple's official security feed has been silent on the matter, but any form of panic would be immature: Kaspersky says the problem only affects OSX10.8.5 running Safari 6.0.5 and OSX 10.7.5 with Safari 6.0.5. Still, even if a small percentage of users can be affected, it would be imperative for Apple to fix the issue.

TOPICS
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras