General

Many Security Flaws in Apple Safari Browser: Google

Author : NewsGram Desk

Google security researchers discovered several security flaws in a privacy software in Apple web browser Safari that could have helped third-party vendors track users' browsing habits.

According to a report in the Financial Times which cited a soon-to-be published paper from Google's 'Project Zero' team, the vulnerabilities were found in an anti-tracking feature known as 'Intelligent Tracking Prevention'.

Once disclosed by Google researchers to Apple in August last year, the Cupertino-based iPhone maker immediately patched the flaws.

Apple launched the 'Intelligent Tracking Prevention' tool in 2017 to, in fact, protect Safari users from being tracked around the web by advertisers and other third-party cookies.

According to Google researchers, the vulnerabilities left personal data of Safari users exposed. They also found a flaw that allowed hackers to "create a persistent fingerprint that will follow the user around the web".

This is the third time Google researchers have found flaws in the Apple ecosystem. Pixabay

Apple confirmed it patched the issues.

This is the third time Google researchers have found flaws in the Apple ecosystem.

In September, Apple slammed Google for creating a false impression about its iPhones being at hacking risk owing to security flaws that allegedly let several malicious websites break into its iOS operating system.

Researchers at 'Project Zero' team had discovered several hacked websites that allegedly used security flaws in iPhones to attack users who visited these websites — compromising their personal files, messages, and real-time location data.

In a statement, Apple said the so-called sophisticated attack was narrowly focused, not a broad-based exploit of iPhones "en masse" as described.

According to Google, the websites delivered their malware indiscriminately and were operational for years.

Apple said that it fixed the vulnerabilities in question — working extremely quickly to resolve the issue just 10 days after it learnt about it.

In July last year, the 'Project Zero' team found six critical flaws in Apple iMessage that can compromise the user's phone without even interacting with them. These security vulnerabilities fell into the 'interactionless' category.

Two members of 'Project Zero', Google's elite bug-hunting team, published details and demo proof-of-concept code for five of six 'interactionless' security bugs that impact the iOS operating system and can be exploited via the iMessage client. All the six security bugs were patched with the iPhone maker's iOS 12.4 release. (IANS)

Subscribe to our channels on YouTube and WhatsApp

Download our app on Play Store

Parliament Monsoon Session LIVE: RS LoP Kharge Says Dharmendra Pradhan Must Resign If Fair Discussion About Paper Leak Case Were To Happen, House Adjourned Till 3pm

CJP Protest March LIVE Updates: CJI Surya Kant Declines Urgent Hearing on Plea Alleging Police Brutality During CJP March, Says, "Don't Waste Our Time"

14 Women Hospitalized After Ammonia Gas Leak at Uttar Pradesh Meat-Processing Plant

India Lodges Strong Protest with Russia Over Cargo Ship Attack that Killed Four Indians

16 Delhi Metro Stations Closed Amid Jantar Mantar Protest