Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    These streaming services have the best offline mode for traveling

    June 8, 2025

    WWDC 2025: What is expected from the Worldwide Developers Conference of Apple Intellization, Apple from iOS 26

    June 8, 2025

    I defeated a bird by talking about the Bible in this low-Fi first-Person RPG, where you are the 19th-century Deman Summer

    June 8, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Apple Safari exposes users to fullscreen browser-in–media attacks
    Security

    Apple Safari exposes users to fullscreen browser-in–media attacks

    PineapplesUpdateBy PineapplesUpdateMay 30, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Apple Safari exposes users to fullscreen browser-in–media attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Apple Safari exposes users to fullscreen browser-in–media attacks

    A weakness in Apple’s Safari web browser allows danger actors to avail fullscreen browser-in-a-mid-middle technology so that they can steal account credentials from unheal users.

    By misusing fullscreen API, which instructs any material on a webpage to enter the browser’s fullscreen viewing mode, hackers can exploit a decrease in chromium-based browsers and trick victims to decrease in typing sensitive data in an attacker-controlled window.

    Squarex researchers used this type of malicious activity and said that such attacks are particularly dangerous for safari users, as Apple’s browser fails to consume users properly when a browser window enters fullscreen mode.

    “Squarex’s research team has seen several examples of the browser’s fullscreen API, which has been exploited to address this defect by displaying fullscreen bitmal window, which covers the address bar of parent window, as well as a limit for safari browsers that specially assures the fullscreen bitter attacks,” Describes the report,

    How the bite works

    A common Bitm attack shows a valid login page that includes users in interaction with an attacker-controlled distance browser. It is obtained through devices such as Novnc – an open -Source VNC browser client, which opens a remote browser at the top of the victim’s session.

    An example of a bitmal attack targeting steam accounts
    Attacker-controlled browser opens the legitimate steam login page in the bitmal attack
    Source: Squarex

    Since the login process occurs in the browser of the attacker, credentials are collected, but the victim also successfully access his account unknown to theft.

    In the attack, the victim still needs to click on a malicious link that redirects them to a fake site that applies the target service. However, it can easily be obtained through advertisements sponsored in web browsers, social media posts, or comments.

    Sponsored advertisement leads to fake fig site
    Promote fake fig site through sponsored advertisements
    Source: Squarex

    Fulscreen deception

    If the users recall the suspected URL in the browser bar and click on the login button, the BITM window becomes activated. Till the trigger, the window was hidden from the victim in minimal mode.

    If the users recall the suspected URL in the browser bar and click on the login button, which activates the bitmal window that was hidden in the minimum mode from the victim.

    Once active, the attacker-controlled browser window enters the fullscreen mode and covers the fake website, which wanted to reach the valid website to the user.

    Security solutions like EDRS or SASE/SSE will not trigger any warnings if this happens, as the attack abuses standard browser API.

    Researchers suggest that firefox and chromium-based browser (eg chrome and edge) whenever fullscreen is active, shows alerts. Although many users can recall warnings, it is still a railing that reduces the risk of the bitmal attack.

    Warning message on firefox (left) and chrome (right)
    Warning message for fullscreen mode on firefox (left) and chrome (right)
    Source: Squarex

    However, there is no alert on the safari and the only sign of a browser entering fullscreen mode is a “swipe” animation that can be easily remembered.

    Squarex researchers say, “While the attack works on all browsers, the fullscreen bite attacks are reassured due to the lack of clear visual signals, especially on the safari browsers.”

    https://www.youtube.com/watch?v=9c4jrabg2cy

    Squarex approached Apple with its findings and received a “wontfix” answer, obtained clarification that animation is present to indicate changes, and it should be enough.

    Bleepingcomputer has also reached Apple for a comment, but we are still waiting for their response.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    Apple attacks browserinmedia exposes fullscreen safari users
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHold this 65W anchor charger for less than $ 30
    Next Article Get one year for only $ 25
    PineapplesUpdate
    • Website

    Related Posts

    Web3

    WWDC 2025: What is expected from the Worldwide Developers Conference of Apple Intellization, Apple from iOS 26

    June 8, 2025
    Security

    Remove project directors presented as malicious NPM package utilities

    June 8, 2025
    How-To

    Visionos 26: We know everything about the next major update of Apple Vision Pro

    June 8, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025594 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025536 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025465 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Meta delay entrusts ‘Bhamoth’ AI model, Openi and Google more than one more head start

    May 16, 20250 Views

    The new coding agent of Chatgpt is very big, even if you are not a programmer

    May 16, 20250 Views

    Google’s AI overview is often wrong with so confident that I have lost all confidence in them

    May 16, 20250 Views
    Our Picks

    These streaming services have the best offline mode for traveling

    June 8, 2025

    WWDC 2025: What is expected from the Worldwide Developers Conference of Apple Intellization, Apple from iOS 26

    June 8, 2025

    I defeated a bird by talking about the Bible in this low-Fi first-Person RPG, where you are the 19th-century Deman Summer

    June 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.