News Blog

News Blog


Apple fixes lingering Java security flaw in Mac software

Apple, security, Mac OS XSix months after the discovery of a security flaw in Apple's implementation of Java software in some versions of the Mac OS X operating system, the company is releasing a fix.

The software flaw could allow a hacker to install and execute malicious software (malware) on Macs running Leopard and some Tiger operating systems. Once onboard the Macs, the malware could be used to steal information from the computers.

Security researchers claim that Apple has been ignoring their warnings about this problem for months. Five months ago the Java vulnerabilities were publicly disclosed, and fixed by Sun Microsystems (the company that developed and maintains Java), according to a May blog post by Landon Fuller, founder of software maker Plausible Labs Cooperative, Inc. in San Francisco and a former Apple programmer. Fuller also published a proof-of-concept hack on his Web site demonstrating how someone could exploit the vulnerability to attack or even take control of another person's Mac, Computer Reseller News (CRN) reports.

Intego, an Austin, Texas, -based maker of Mac security software, last month also issued a warning for Mac users to disable Java in their Web browsers until Apple got around to fixing the Java vulnerability, reports InformationWeek. The flaw in Java, a programming language Sun introduced in 1995 to allow the same software to run on many different computer platforms, could allow Mac users to be attacked simply by visiting a Web site containing malware designed to exploit the flaw (also known as "drive-by" attacks). Hackers writing such malware could then access or delete files on the vulnerable Mac, according to Intego.

While Washington Post computer security reporter Brian Krebs writes that Apple has a history of patching Java flaws on average about six months after Sun has fixed them, Apple is far from the only big software company known to drag its feet when fixing problems with its products. Microsoft, Oracle, Cisco and others have been known to take a reactive (rather than proactive) approach toward disclosing and fixing security flaws in their software, sometimes prompting security experts to (as Fuller did) write and publish blueprints for exploiting those flaws.

One of the most infamous examples of this came at the Black Hat security conference in July 2005 when then-24-year-old security expert Michael Lynn gave a presentation demonstrating how to take control of Cisco network routers thanks to a security hole in Cisco's software. When Cisco got wind of what Lynn was doing at the conference, the company demanded that Black Hat remove Lynn's presentation from its conference handouts and got a court order to prevent Lynn from ever giving his presentation again. Cisco claimed that it had already issued a patch for the problem in April 2005, but Lynn countered that Cisco underplayed to customers the seriousness of the security problem, so many had not bothered to install it.

Image ©iStockphoto.com/ Robert Koopmans

Tags: security, Mac OS X, Microsoft, Apple, Oracle, Cisco, Michael Lynn, malware
More News Blog: Next: Snakes rattle war-torn Iraq Previous: Government report says snowmobiling, maple syrup, and lobster fishing are being hurt by climate change

4 Comments

Add Comment
View
  1. 1. candide 05:29 PM 6/16/09

    If MS did this they would be excoriated in the media.

    Reply | Report Abuse | Link to this
  2. 2. asozasis 09:19 AM 6/17/09

    @ candide: the rotten apple pic is not excoriation?

    Reply | Report Abuse | Link to this
  3. 3. jrlopezp 08:26 AM 6/18/09

    The rotten apple pic is not excoriation. A bunch of journalists use Mac and that's probably why media coverage on this was less than it would have been expected since it took them SIX months to roll out a fix. I'll say, Mac does know how to take advantage of tv commercials about PC's vulnerablilties though... but they are in the same boat. As more people adopt Mac, more exploits will be found. My two cents.

    Reply | Report Abuse | Link to this
  4. 4. asozasis in reply to jrlopezp 09:36 AM 6/18/09

    @jrlopezp: Fair enough. Apple in question still has core, therefore NOT excored.

    Reply | Report Abuse | Link to this
Leave this field empty

Add a Comment

You must sign in or register as a ScientificAmerican.com member to submit a comment.
Click one of the buttons below to register using an existing Social Account.

More from Scientific American

See what we're tweeting about

Scientific American Editors

More »

Free Newsletters


Get the best from Scientific American in your inbox

Solve Innovation Challenges

Powered By: Innocentive

  SA Digital
  SA Digital

Email this Article

Apple fixes lingering Java security flaw in Mac software : Scientific American Blog

X
Scientific American Magazine

Subscribe Today

Save 66% off the cover price and get a free gift!

Learn More >>

X

Please Log In

Forgot: Password

X

Account Linking

Welcome, . Do you have an existing ScientificAmerican.com account?

Yes, please link my existing account with for quick, secure access.



Forgot Password?

No, I would like to create a new account with my profile information.

Create Account
X

Report Abuse

Are you sure?

X

Institutional Access

It has been identified that the institution you are trying to access this article from has institutional site license access to Scientific American on nature.com. To access this article in its entirety through site license access, click below.

Site license access
X

Error

X

Share this Article

X

About the Bering in Mind Blog

In this column presented by Scientific American Mind magazine, research psychologist Jesse Bering of Queen's University Belfast ponders some of the more obscure aspects of everyday human behavior. Ever wonder why yawning is contagious, why we point with our index fingers instead of our thumbs or whether being breastfed as an infant influences your sexual preferences as an adult? Get a closer look at the latest data as "Bering in Mind" tackles these and other quirky questions about human nature. Sign up for the RSS feed or friend Dr. Bering on Facebook and never miss an installment again.

X

About the Cross-check Blog

Every week, John Horgan takes a puckish, provocative look at breaking science. A former staff writer at Scientific American, he is the author of several books—most notably, The End of Science: Facing the Limits of Knowledge in the Twilight of the Scientific Age. He currently directs the Center for Science Writings at Stevens Institute of Technology. He lives in New York State's Hudson Highlands, where he plays ice hockey each winter to hone his cross-checking skills.

X

Expeditions Blog

Ever wonder what it's really like to be working in Antarctica or collecting core samples from the middle of the Pacific Ocean? Get a first-hand feel for scientific exploration by following the blog posts of researchers out in the field.

X

About the Extinction Countdown Blog

Several times a week, John Platt shines a light on endangered species from all over the globe, exploring not just why they are dying out but also what's being done to rescue them from oblivion. From unusual or little-known organisms like the giant spitting earthworm and the stinking hawk's-beard to popular favorites like cheetahs and koalas, Platt, a journalist specializing in environmental issues and technology, does his part to slow the countdown.

X

About the Guest Blog

The editors of Scientific American regularly encounter perspectives on science and technology that we believe our readers would find thought-provoking, fascinating, debatable and challenging. The guest blog is a forum for such opinions. The views expressed belong to the author and are not necessarily shared by Scientific American.

X

About the Solar at Home Blog

Follow Scientific American editor George Musser as he installs--or tries to install--solar photovoltaic panels on the roof of his suburban New Jersey home. You'll learn the literal nuts and bolts of going green with the sun and get energy-saving tips even if you aren't putting up panels.

Write to us with tips or comments at blog@sciam.com and follow us on Twitter: http://twitter.com/sciam.

X