Security outfit Secunia said that a vulnerability and "proof of concept" code to exploit released on Wednesday as part of the Month of Apple Bugs project was valid. The flaw affects Mac OS X 10.4.8, the most recent version of Apple's operating system and, possibly, previous versions.
Secunia said the problem is "highly critical" particularly as many Apple users have a falsely inflated sense of security.
The security outfit said users should disable this automatic feature in Safari. Security boffins have been getting increasingly tetchy with Apple over its "open safe" feature as the company does not completely close up security holes.
Open save automatically opens files that are deemed to be safe which is a target for hackers. Apple attempted to add a "download validation" function to the tool to warn people when they may be downloading something nasty.
But security boffins say it is dead easy for hackers to create a file that appears to be safe but is really dangerous.
More here. ยต