logo

Apple Safari exposes users to fullscreen browser-in-the-middle attacks

ID: c0fc0ec0-6b54-5088-a270-f09375851f4d

STIX ID: report--c0fc0ec0-6b54-5088-a270-f09375851f4d

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2025-05-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

SquareX researchers describe a weakness in Safari's handling of the Fullscreen API that enables fullscreen browser-in-the-middle (BitM) attacks: attackers can open a remote, attacker-controlled browser (via tools like noVNC), activate a fullscreen window that covers the address bar and other guardrails, and harvest credentials when victims log in. Chromium and Firefox show fullscreen warnings that can mitigate the risk, but Safari lacks a clear alert, increasing the likelihood of successful credential theft; SquareX reported the issue to Apple and received a "wontfix" response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.