Apple Computer yesterday released its first security update of 2006 to patch 17 bugs, including a critical flaw in the Safari browser and a loophole used by the first Mac OS X virus to infect Macs, reports InformationWeek. The update comes only a week or so after news of a critical flaw in the operating system and the Safari browser. The Safari vulnerability stemmed from Safari's (and Mac OS X's) trust of certain file types, specifically ZIP archives, which could be used to hide malicious scripts that the Mac would automatically run.
"This update addresses the issue by performing additional download validation so that the user is warned (in Mac OS X v10.4.5) or the download is not automatically opened (in Mac OS X v10.3.9)," Apple's alert read.