Apple Mail spoofing problem
Secure OS X has discovered a
The vulnerability involves the way links are displayed in HTML messages in certain circumstances:
The WebKit application fails to show the correct URL in the status bar if an image control with a “title” attribute has been enclosed in a hyperlink and uses a form to specify the destination URL. This may cause a user to follow a link to a seemingly trusted website when in fact the browser opens a malicious website.
Secure OS X recommends being careful when entering personal information after following a link contained in an email.
It also suggests viewing the raw source of the message if you are at all suspicious — View > Message > Raw Source in the menus, or Option-Command-U — to see what the URL reallly is before clicking on it.
Tags: Apple Mail, HTML, mail.app, spoofing, WebKitRelated posts
