This worrying Apple Safari security bug could leave users wide open to cyberattacks

This worrying Apple Safari security bug could leave users wide open to cyberattacks

This worrying Apple Safari security bug could leave users wide open to cyberattacks


  • SquareX says hackers can abuse the Fullscreen API in Safari to trick people into running remote browsers
  • The browser-in-the-middle attack is good for stealing login credentials
  • Apple says guardrails are in place and will not pursue it further

Fullscreen API, a functionality in the Apple Safari browser which allows web developers to present specific elements in fullscreen mode, has a vulnerability that is being abused in convincing password theft attacks, experts have warned.

Security researchers SquareX claim to have observed an increase in use in this type of attack, which leverages the browser-in-the-middle (Bitm) technique.

Leave a Comment

Your email address will not be published. Required fields are marked *