Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Apple Safari exposes users to fullscreen browser-in–media attacks
    Security

    Apple Safari exposes users to fullscreen browser-in–media attacks

    PineapplesUpdateBy PineapplesUpdateMay 30, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Apple Safari exposes users to fullscreen browser-in–media attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Apple Safari exposes users to fullscreen browser-in–media attacks

    A weakness in Apple’s Safari web browser allows danger actors to avail fullscreen browser-in-a-mid-middle technology so that they can steal account credentials from unheal users.

    By misusing fullscreen API, which instructs any material on a webpage to enter the browser’s fullscreen viewing mode, hackers can exploit a decrease in chromium-based browsers and trick victims to decrease in typing sensitive data in an attacker-controlled window.

    Squarex researchers used this type of malicious activity and said that such attacks are particularly dangerous for safari users, as Apple’s browser fails to consume users properly when a browser window enters fullscreen mode.

    “Squarex’s research team has seen several examples of the browser’s fullscreen API, which has been exploited to address this defect by displaying fullscreen bitmal window, which covers the address bar of parent window, as well as a limit for safari browsers that specially assures the fullscreen bitter attacks,” Describes the report,

    How the bite works

    A common Bitm attack shows a valid login page that includes users in interaction with an attacker-controlled distance browser. It is obtained through devices such as Novnc – an open -Source VNC browser client, which opens a remote browser at the top of the victim’s session.

    An example of a bitmal attack targeting steam accounts
    Attacker-controlled browser opens the legitimate steam login page in the bitmal attack
    Source: Squarex

    Since the login process occurs in the browser of the attacker, credentials are collected, but the victim also successfully access his account unknown to theft.

    In the attack, the victim still needs to click on a malicious link that redirects them to a fake site that applies the target service. However, it can easily be obtained through advertisements sponsored in web browsers, social media posts, or comments.

    Sponsored advertisement leads to fake fig site
    Promote fake fig site through sponsored advertisements
    Source: Squarex

    Fulscreen deception

    If the users recall the suspected URL in the browser bar and click on the login button, the BITM window becomes activated. Till the trigger, the window was hidden from the victim in minimal mode.

    If the users recall the suspected URL in the browser bar and click on the login button, which activates the bitmal window that was hidden in the minimum mode from the victim.

    Once active, the attacker-controlled browser window enters the fullscreen mode and covers the fake website, which wanted to reach the valid website to the user.

    Security solutions like EDRS or SASE/SSE will not trigger any warnings if this happens, as the attack abuses standard browser API.

    Researchers suggest that firefox and chromium-based browser (eg chrome and edge) whenever fullscreen is active, shows alerts. Although many users can recall warnings, it is still a railing that reduces the risk of the bitmal attack.

    Warning message on firefox (left) and chrome (right)
    Warning message for fullscreen mode on firefox (left) and chrome (right)
    Source: Squarex

    However, there is no alert on the safari and the only sign of a browser entering fullscreen mode is a “swipe” animation that can be easily remembered.

    Squarex researchers say, “While the attack works on all browsers, the fullscreen bite attacks are reassured due to the lack of clear visual signals, especially on the safari browsers.”

    https://www.youtube.com/watch?v=9c4jrabg2cy

    Squarex approached Apple with its findings and received a “wontfix” answer, obtained clarification that animation is present to indicate changes, and it should be enough.

    Bleepingcomputer has also reached Apple for a comment, but we are still waiting for their response.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    Apple attacks browserinmedia exposes fullscreen safari users
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHold this 65W anchor charger for less than $ 30
    Next Article Get one year for only $ 25
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    Verizon outage affects more than 2 million users: What ‘SOS’ means, refunds, more updates

    January 15, 2026
    Startups

    I watched a live NBA game for 3 hours on Apple Vision Pro – it disappointed me in the best way

    January 14, 2026
    Startups

    Avoiding the iOS 26 update? 4 reasons why iPhone users should do this – ASAP

    January 13, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Google tests AI-operated audio overview in search results for some questions

    June 16, 20250 Views

    Yes, this was the original voice of the Garat in the trailer for the thief VR

    June 16, 20250 Views

    Best LC10 loadout in call of duty: Warzone

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.