August 8th, 2024

Apple to Address '0.0.0.0' Security Vulnerability in Safari 18

Apple will address a security vulnerability in Safari 18 affecting macOS Sequoia, Sonoma, and Ventura, blocking malicious requests to the IP address 0.0.0.0, with an update expected later this year.

Read original articleLink Icon
Apple to Address '0.0.0.0' Security Vulnerability in Safari 18

Apple is set to address a significant security vulnerability in Safari 18, which affects macOS Sequoia, Sonoma, and Ventura. The vulnerability, identified by researchers from Oligo Security, involves the IP address 0.0.0.0, which can be exploited by malicious actors to access private data on a user's internal network. This zero-day vulnerability allows attackers to open various attack vectors against victims. The researchers will present their findings at the DEF CON hacking conference in Las Vegas. Apple, along with Google and Mozilla, has been informed of the issue through responsible disclosure. The upcoming Safari 18 update, currently in beta, aims to block websites from sending harmful requests to the 0.0.0.0 address. The official release of macOS Sequoia and Safari 18 is expected later this year.

- Apple will block malicious requests to the IP address 0.0.0.0 in Safari 18.

- The vulnerability allows attackers to access private data on internal networks.

- Researchers from Oligo Security discovered the issue and will present findings at DEF CON.

- The update will be included in macOS Sequoia, Sonoma, and Ventura.

- Safari 18 is currently in beta and will be released later this year.

Link Icon 3 comments
By @sphars - 5 months
By @venusenvy47 - 5 months
I like how the article refers to it as 0.0.0.0-day
By @th3w3bmast3r - 5 months
Big oof!