Apple: Not so Bullet-proof

Java Vulnerability Exploited

Apple has admitted that they were targeted recently in a carefully orchestrated attack.  The Cupertino company also just released a patch and fix for the vulnerability.

In an email, Apple provided Macworld with a statement on the breach, saying:

Apple has identified malware which infected a limited number of Mac systems through a vulnerability in the Java plug-in for browsers. The malware was employed in an attack against Apple and other companies, and was spread through a website for software developers. We identified a small number of systems within Apple that were infected and isolated them from our network. There is no evidence that any data left Apple. We are working closely with law enforcement to find the source of the malware.

Since OS X Lion, Macs have shipped without Java installed, and as an added security measure OS X automatically disables Java if it has been unused for 35 days. To protect Mac users that have installed Java, today we are releasing an updated Java malware removal tool that will check Mac systems and remove this malware if found.

(Visited 24 times, 1 visits today)