Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Babylon BTC introduces trusted bitcoin vaults for the stacking protocol

    August 6, 2025

    Google said AI search facilities website is killing traffic

    August 6, 2025

    Learn to raise a seed round from top VC to interrupt 2025

    August 6, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Apple Safari exposes users to fullscreen browser-in–media attacks
    Security

    Apple Safari exposes users to fullscreen browser-in–media attacks

    PineapplesUpdateBy PineapplesUpdateMay 30, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Apple Safari exposes users to fullscreen browser-in–media attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Apple Safari exposes users to fullscreen browser-in–media attacks

    A weakness in Apple’s Safari web browser allows danger actors to avail fullscreen browser-in-a-mid-middle technology so that they can steal account credentials from unheal users.

    By misusing fullscreen API, which instructs any material on a webpage to enter the browser’s fullscreen viewing mode, hackers can exploit a decrease in chromium-based browsers and trick victims to decrease in typing sensitive data in an attacker-controlled window.

    Squarex researchers used this type of malicious activity and said that such attacks are particularly dangerous for safari users, as Apple’s browser fails to consume users properly when a browser window enters fullscreen mode.

    “Squarex’s research team has seen several examples of the browser’s fullscreen API, which has been exploited to address this defect by displaying fullscreen bitmal window, which covers the address bar of parent window, as well as a limit for safari browsers that specially assures the fullscreen bitter attacks,” Describes the report,

    How the bite works

    A common Bitm attack shows a valid login page that includes users in interaction with an attacker-controlled distance browser. It is obtained through devices such as Novnc – an open -Source VNC browser client, which opens a remote browser at the top of the victim’s session.

    An example of a bitmal attack targeting steam accounts
    Attacker-controlled browser opens the legitimate steam login page in the bitmal attack
    Source: Squarex

    Since the login process occurs in the browser of the attacker, credentials are collected, but the victim also successfully access his account unknown to theft.

    In the attack, the victim still needs to click on a malicious link that redirects them to a fake site that applies the target service. However, it can easily be obtained through advertisements sponsored in web browsers, social media posts, or comments.

    Sponsored advertisement leads to fake fig site
    Promote fake fig site through sponsored advertisements
    Source: Squarex

    Fulscreen deception

    If the users recall the suspected URL in the browser bar and click on the login button, the BITM window becomes activated. Till the trigger, the window was hidden from the victim in minimal mode.

    If the users recall the suspected URL in the browser bar and click on the login button, which activates the bitmal window that was hidden in the minimum mode from the victim.

    Once active, the attacker-controlled browser window enters the fullscreen mode and covers the fake website, which wanted to reach the valid website to the user.

    Security solutions like EDRS or SASE/SSE will not trigger any warnings if this happens, as the attack abuses standard browser API.

    Researchers suggest that firefox and chromium-based browser (eg chrome and edge) whenever fullscreen is active, shows alerts. Although many users can recall warnings, it is still a railing that reduces the risk of the bitmal attack.

    Warning message on firefox (left) and chrome (right)
    Warning message for fullscreen mode on firefox (left) and chrome (right)
    Source: Squarex

    However, there is no alert on the safari and the only sign of a browser entering fullscreen mode is a “swipe” animation that can be easily remembered.

    Squarex researchers say, “While the attack works on all browsers, the fullscreen bite attacks are reassured due to the lack of clear visual signals, especially on the safari browsers.”

    https://www.youtube.com/watch?v=9c4jrabg2cy

    Squarex approached Apple with its findings and received a “wontfix” answer, obtained clarification that animation is present to indicate changes, and it should be enough.

    Bleepingcomputer has also reached Apple for a comment, but we are still waiting for their response.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    Apple attacks browserinmedia exposes fullscreen safari users
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHold this 65W anchor charger for less than $ 30
    Next Article Get one year for only $ 25
    PineapplesUpdate
    • Website

    Related Posts

    Security

    My new favorite kitchen holder can carry up to 14 keys (and is trackable by phone)

    August 6, 2025
    Security

    New ghosts for C2 operations misused strategy and call Microsoft teams

    August 6, 2025
    Security

    Spylaud AI-Inaccurates enhances the investigation solution with an insight-irritable formula in danger and cyber crime analysis revolution

    August 6, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Babylon BTC introduces trusted bitcoin vaults for the stacking protocol

    August 6, 2025

    Google said AI search facilities website is killing traffic

    August 6, 2025

    Learn to raise a seed round from top VC to interrupt 2025

    August 6, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.