With the excitement surrounding Apple’s iPhone 4 at its World Wide Developer Conference (WWDC) yesterday, Apple decided not talk about the latest version of its Web browser during the Keynote, instead making the announcement and releasing the product later in the day. In addition to expanded HTML5 support, an upgraded “Nitro JavaScript Engine” and other features, Safari 5 adds some enhanced performance and security features useful to both developers and end users.
With the release of Safari 5, Apple will provide Safari developers with tools to create a digital certificate for extensions. Safari extensions must be signed with an Apple-provided digital certificate. The certificate protects the extensions from tampering and ensures that updates come only from the developer that owns it.
In addition, Safari extensions include built-in defenses like sandboxing which safeguards extensions from being used to access information on a user’s system. Built with standard web technologies, Safari extensions execute right in the browser, reducing the chance of an extension causing crashes or instability.
While not exactly a pure “security” feature, an improved Web Inspector lets users view how Safari interacts with websites. Loading, scripting, and rendering timelines show how and when Safari parses HTML, executes JavaScript, and performs other operations with a web application. Additional improvements to the Web Inspector make it easy for developers to pinpoint areas for optimization and can be a useful tool for security researchers and QA teams.
In addition to new security features and functions, Apple also fixed other vulnerabilities including CSS history hacks, potential HTTPS to HTTPS data leaks and more. A full detail of the security content for Safari 5 is available here.
Safari 5 is available for download at: http://www.apple.com/safari/download/

More from SecurityWeek News
- Threat Hunting Summit Virtual Event NOW LIVE
- Video: ESG – CISO’s Guide to an Emerging Risk Cornerstone
- Threat Modeling Firm IriusRisk Raises $29 Million
- SentinelOne Announces $100 Million Venture Fund
- Today: 2022 CISO Forum Virtual Event
- Cymulate Closes $70M Series D Funding Round
- SecurityWeek to Host CISO Forum Virtually September 13-14, 2022: Registration is Open
- Privilege Escalation Flaw Haunts VMware Tools
Latest News
- In Other News: AI Regulation, Layoffs, US Aerospace Attacks, Post-Quantum Encryption
- Blackpoint Raises $190 Million to Help MSPs Combat Cyber Threats
- Google Introduces SAIF, a Framework for Secure AI Development and Use
- ‘Asylum Ambuscade’ Group Hit Thousands in Cybercrime, Espionage Campaigns
- Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021
- SaaS Ransomware Attack Hit Sharepoint Online Without Using a Compromised Endpoint
- Google Cloud Now Offering $1 Million Cryptomining Protection
- Democrats and Republicans Are Skeptical of US Spying Practices, an AP-NORC Poll Finds
