苹果今天为 OS X Yosemite 系统发布了 Safari 8.0.6,提升了系统的安全性。此外,苹果还为 Mavericks 用户发布了 Safari 7.1.6 和 Mountain Lion 用户发布了 Safari 6.2.6 安全升级补丁。根据苹果安全支持文档,升级修复了可以导致行任意代码或泄露个人信息的 WebKit 安全漏洞。
苹果建议所有 OS X Yosemite 用户升级至 Safari 8.0.6,用户可以通过 Mac App Store 完成更新。Safari 8.0.6 距离 Safari 8.0.5 相隔一个月的时间。Safari 8.0.5 属于 OS X Yosemite 10.10.3 的一部分,在4月8日发布。
更新列表:
WebKit
Available for: OS X Mountain Lion v10.8.5, OS X Mavericks v10.9.5, and OS X Yosemite v10.10.3
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: Multiple memory corruption issues existed in WebKit. These issues were addressed through improved memory handling.
WebKit History
Available for: OS X Mountain Lion v10.8.5, OS X Mavericks v10.9.5, and OS X Yosemite v10.10.3
Impact: Visiting a maliciously crafted website may compromise user information on the filesystem
Description: A state management issue existed in Safari that allowed unprivileged origins to access contents on the filesystem. This issue was addressed through improved state management.
WebKit Page Loading
Available for: OS X Mountain Lion v10.8.5, OS X Mavericks v10.9.5, and OS X Yosemite v10.10.3
Impact: Visiting a malicious website by clicking a link may lead to user interface spoofing
Description: An issue existed in the handling of the rel attribute in anchor elements. Target objects could get unauthorized access to link objects. This issue was addressed through improved link type adherence.