Mobile menu toggle

Safari exploit allows attackers to spoof URLs

By •

Whatever, Safari. I'm not believing a thing you say anymore.
Whatever, Safari. I'm not believing a thing you say anymore.
Screenshot: Evan Killham/Cult of Mac

Tech-wizard scientists have discovered a crack in the Safari web browser’s armor that will let evildoers trick it into showing false information in its address bar.

The exploit could lead to users giving up sensitive information when they think they’re just trying to buy some pants or something.

Security firm Deusen, which uncovered a serious bug in Internet Explorer back in February, showed the trick to Ars Technica. The exploit works by using a short script to force Safari to load another page while still displaying the URL for the original destination (see above).

Deusen has posted its demonstration online. Clicking “Go” on that page in Safari will return the reality-bending, not-Daily Mail page. If you click it in Chrome, however, it’ll just twitch around a lot and then send you to the real Daily Mail.

… or does it?

I don’t know what’s real anymore.

  • Subscribe to the Newsletter

    Our daily roundup of Apple news, reviews and how-tos. Plus the best Apple tweets, fun polls and inspiring Steve Jobs bons mots. Our readers say: "Love what you do" -- Christi Cardenas. "Absolutely love the content!" -- Harshita Arora. "Genuinely one of the highlights of my inbox" -- Lee Barnett.

4 responses to “Safari exploit allows attackers to spoof URLs”

  1. niji says:

    that is interesting.

    but what also is true, is that in the above exploit, if you click in the Address Bar (using Safari) you get a strange behavior that seems to be forcing the Address Bar to attempt to show you the real address but it quickly resolves back to the fake address.

    of course, if you chose “show full address” in Safari advanced tab of its preferences, the exploit’s behavior is also really interesting: you can actually see it changing the the last 10 or so address digits every half second or so.

  2. Vincent Perro says:

    Don’t you know how to deal with it?=) Switching to some decent browser like Chrome or Firefox can help ;) No, really, who uses safari, it’s sooo bad, i’ve got all kinds of apple devises but they all run chrome.

Leave a Reply