• This forum is for posting news stories or links from rumor sites. When you start a thread, please include a link to the site you're referencing.

    THIS IS NOT A FORUM TO ASK "WHAT IF?" TYPE QUESTIONS.

    THIS IS NOT A FORUM FOR ASKING QUESTIONS ABOUT HOW TO USE YOUR MAC OR SOFTWARE.

    This is a NEWS and RUMORS forum as the name implies. If your thread is neither of those things, then please find the appropriate forum to ask your question.

    If you don't have a link to a news story, do not post the thread here.

    If you don't follow these rules, then your post may be deleted.

Security companies warn of unpatched Java exploit on Mac OS X

cwa107


Retired Staff
Joined
Dec 20, 2006
Messages
27,042
Reaction score
812
Points
113
Location
Lake Mary, Florida
Your Mac's Specs
14" MacBook Pro M1 Pro, 16GB RAM, 1TB SSD
I'm typically skeptical of these, but this one seems legit - and if executed has the potential to be very bad:

Several Mac security companies, Intego and SecureMac, have issued warnings related to an unpatched Java vulnerability that affects OS X. The flaw could be exploited to allow local code to be executed remotely, leaving the computer open to "drive-by-attacks" which can install malicious software just by loading a website containing a specially crafted Java applet. Hackers could also access or delete files on a system.

Full article here.

If you are concerned (and IMO, you should be), a temporary fix would be to turn Java off in the browser of your choice. Although some sites launch Java applets, they should be relatively few (don't confuse Javascript with Java). So for many of you, there will be little impact to your day-to-day web browsing in turning off Java.
 
Joined
Nov 28, 2007
Messages
25,564
Reaction score
486
Points
83
Location
Blue Mountains NSW Australia
Your Mac's Specs
Silver M1 iMac 512/16/8/8 macOS 11.6
Great advice cwa107. Keep us posted on developments please?
 
Joined
Feb 1, 2009
Messages
95
Reaction score
2
Points
8
Location
New York
Your Mac's Specs
Mini 1.83Ghz Dual Core, 2 GB RAM, running 10.6.1
Disable Java in Firefox:

Firefox Menu > Preferences > Content Tab

Picture 1.png
 

vansmith

Senior Member
Joined
Oct 19, 2008
Messages
19,924
Reaction score
559
Points
113
Location
Queensland
Your Mac's Specs
Mini (2014, 2018, 2020), MBA (2020), iPad Pro (2018), iPhone 13 Pro Max, Watch (S6)
While I do espouse security as an important part of daily use, this exploit doesn't seem to bother me. Disabling Java should work and prevent users from themselves (the cause of most computer problems). I think the part that's bothering me most about this exploit is not the exploit itself but Apple's continued disregard for Java. For a company that want's to be on the edge, they sure don't seem quick to defend and patch the arguably most used programming language in the world (last I heard).
 
OP
cwa107

cwa107


Retired Staff
Joined
Dec 20, 2006
Messages
27,042
Reaction score
812
Points
113
Location
Lake Mary, Florida
Your Mac's Specs
14" MacBook Pro M1 Pro, 16GB RAM, 1TB SSD
While I do espouse security as an important part of daily use, this exploit doesn't seem to bother me. Disabling Java should work and prevent users from themselves (the cause of most computer problems). I think the part that's bothering me most about this exploit is not the exploit itself but Apple's continued disregard for Java. For a company that want's to be on the edge, they sure don't seem quick to defend and patch the arguably most used programming language in the world (last I heard).

Agreed. As much as Apple likes to promote the security of Mac OS X, they do seem slow to address high-profile exploits like this. As I understand it, this one has been in the wild for something like 6 months.
 

vansmith

Senior Member
Joined
Oct 19, 2008
Messages
19,924
Reaction score
559
Points
113
Location
Queensland
Your Mac's Specs
Mini (2014, 2018, 2020), MBA (2020), iPad Pro (2018), iPhone 13 Pro Max, Watch (S6)
Agreed. As much as Apple likes to promote the security of Mac OS X, they do seem slow to address high-profile exploits like this. As I understand it, this one has been in the wild for something like 6 months.
I read nine months. Either way, both times are well too long for such an important program. As much as I like Apple, I do have a few problems with the way they approach things. One of them is that is seems as if the "security through obscurity" myth is their motto in the security department ;).
 

vansmith

Senior Member
Joined
Oct 19, 2008
Messages
19,924
Reaction score
559
Points
113
Location
Queensland
Your Mac's Specs
Mini (2014, 2018, 2020), MBA (2020), iPad Pro (2018), iPhone 13 Pro Max, Watch (S6)
Not good in that it illustrates the trivial nature of the exploit but very good for me (at least) in that it will hopefully get Apple moving on this.

This is why I wish Apple hadn't taken control of Java on the Mac. Since it says that OpenJDK isn't affected, the nerd in me is tempted to try and build OpenJDK tonight.
 
Joined
Apr 29, 2008
Messages
207
Reaction score
1
Points
18
Location
Potsdam NY
Your Mac's Specs
15" MBP, 4GB, 250GB HDD-2.53C2D
disabled it for Safari 4 as well
 
Joined
Apr 7, 2009
Messages
3,308
Reaction score
58
Points
48
Location
Whangarei NZ
Your Mac's Specs
27 iMac+Thunderbolt, iMac 21,
So for those of us that are non techie - should we be unchecking Enable Java or Enable JavaScript in prefs of Safari 3? Or does Enable plug-ins feature as well?
 

vansmith

Senior Member
Joined
Oct 19, 2008
Messages
19,924
Reaction score
559
Points
113
Location
Queensland
Your Mac's Specs
Mini (2014, 2018, 2020), MBA (2020), iPad Pro (2018), iPhone 13 Pro Max, Watch (S6)
I believe the problem is S Jobs has made very negative comments about Java in recent months (do a Google) so I doubt any fixes will come along.

Richard Sprague WebLog : Steve Jobs says Java is history
Agreed. As I linked to earlier, Jobs called it a "'Heavyweight' in an Age of Lightweight Computing." I think that's a bit much.

So for those of us that are non techie - should we be unchecking Enable Java or Enable JavaScript in prefs of Safari 3? Or does Enable plug-ins feature as well?
If you want to be super safe, you should just have to disable Java. Javascript, on the other hand, has nothing to do with Java (despite the name). Otherwise, just be a smart computer user.
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top