QuickTime browser bug puts your PC at risk

A flaw in the latest version of QuickTime could leave your PC open to a malicious attack

Apple's QuickTime media player is in trouble again - this time for a year-old exploit in a browser plug-in that opens up your PC to malicious attack. Firefox's creator Mozilla is so concerned by the threat that its head of security, Window Snyder, has labelled the threat "very serious".

The flaw can be found in QuickTime's MediaLInk (.qtl) function, which enables the program to parse up to 60 different file types with a compatible extension, says Macworld UK. Because XML files are parsed unsanitised, this gives hackers the opportunity to create a link to a malicious JavaScript file and have it run automatically in QuickTime.

The flaw appears to cause particular problems with Firefox, hence Mozilla's concern. By contrast, users of Internet Explorer and Opera on the PC are reporting few or zero problems when running proof-of-concept samples developed by UK-based application tester Petko Petkov. Mac users are also reporting zero problems running Firefox in Mac OS X.

Firefox partly to blame?

While Apple is undoubtedly to blame for the exploit, some security experts are also pointing the finger at Firefox too. The exploit can reportedly bypass 'chrome' privileges in the browser and its built-in security features.

Apple and Mozilla are said to be working together on a fix, but until that happens your best bet is to disable the QuickTime plug-in in whichever web browser you use.

The cross-platform QuickTime media player has suffered from a number of security problems in the last 12 months, forcing Apple to release four security updates for the program. One flaw enabled a worm to be spread across the MySpace social networking site.

TOPICS
Latest in Windows PCs
Dell XPS 13 and Alienware M16 laptops on purple background with big savings text overlay
Dell's site-wide Tech Days sale is live: see the 6 best laptop and gaming laptop deals from just $299
Microsoft presenting Surface Laptop and Surface Pro devices.
Microsoft has pulled a miracle: its Surface Copilot PCs are now the most repairable in the market
asian woman using laptop at business table
Finally, some good Copilot news: Microsoft could be making 16GB RAM a standard for AI PCs
The Acer Predator Orion 3000 gaming PC on a blue and pink background with the text 'TechRadar Cyber Monday PC deals'.
Cyber Monday PC deals 2023 – the best extended deals still live
The Microsoft Outlook logo on a laptop screen
Two unloved Windows 11 apps are getting canned - but will their replacement be any better?
Business man holding a tablet
The PCs protecting workers on the move
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring