Safari’s Fullscreen Flaw: The Browser-in-the-Middle Attack Catching Users Off Guard

SquareX has unveiled a new Browser-in-the-Middle (BitM) attack targeting Safari, exploiting a Fullscreen API flaw. This cunning trickery makes it easier for attackers to steal credentials from unsuspecting users, with no visual clues to alert them. It’s a wake-up call for enterprises to beef up their browser security.

Pro Dashboard

Hot Take:

Safari users, beware! Your browser has become the unwelcome star of the latest cybersecurity horror show. While you’re enjoying the seamless browsing experience, hackers are creating a full-screen fiasco that could trick even the savviest among us. It’s like a magic trick, but with your personal data at stake! Fullscreen API, more like Fullscreen A-PIe in the face, am I right?

Key Points:

  • SquareX unveils a new Browser-in-the-Middle (BitM) attack targeting Safari’s Fullscreen API.
  • BitM attacks deceive users into providing credentials via an attacker-controlled browser window.
  • Safari’s lack of clear fullscreen indicators makes it particularly vulnerable.
  • Other browsers have subtle fullscreen notifications, still offering some protection.
  • Traditional security solutions fail to detect these advanced BitM attacks.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?