Safari now suffers from new exploit allowing malicious website to render arbitrary webpage and extract information out of it.
As of now, there is a workaround requiring access to developer menu on macOS.
Paste the following command in Terminal:
defaults write com.apple.Safari IncludeInternalDebugMenu 1
Open Safari and select “Debug” from the menu bar, select “WebKit Internal Features” then Scroll down and click “Swap Processes on Cross-Site Window Open”
AppleInsider
It is expected that this vulnerability will be fixed by Apple in upcoming software updates.
Disclosure: iLeakage
References:
- iLeakage attack resurrects Spectre with password and website data extraction
- iLeakage flaw could force iPhones and Macs to divulge passwords and more
Recommendations
Developer:
Beware of iLeakage issue. Avoid untrusted web sites.QA engineer:
Beware of iLeakage issue. Avoid untrusted web sites.PM/DM:
Beware of iLeakage issue. Avoid untrusted web sites.