/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Apple Mail in Leopard with the same old error

In March 2006 Apple defused a security problem in Apple Mail that made it possible to inject disguised malignant code.  In Leopard, the patch was apparently forgotten.  This means that you can inadvertently start an executable by double-clicking …

heise Security

Context & Ripple Effects

Leopard has had a rough first month with security reviewers: heise flagged chinks in its armour at the October 2007 launch, and days later Apple conceded its new firewall settings were 'misleading'. Now heise reports a regression rather than a fresh flaw: an Apple Mail code-injection bug that Apple patched back in March 2006 is live again in Leopard.

The Register picked up the story the same day, so this is the third distinct Leopard security criticism to travel widely within three weeks of release. A previously fixed vulnerability shipping unfixed in a major OS upgrade is a different kind of failure than a design choice — it points at patch-regression testing, not just configuration defaults.

First-order effects

  • Leopard users running Apple Mail can be tricked into launching a disguised malicious executable by double-clicking an attachment, re-exposing them to an attack class closed since March 2006.
  • Apple has to ship a corrective patch for code it had already fixed once, spending engineering time on a known defect during the post-launch window.

Second-order effects

  • Coming on top of the firewall controversy, the regression hands security researchers a narrative that Leopard's hardening was rushed, raising the cost of Apple's 'it just works' positioning against Windows Vista's security messaging.
  • Enterprises weighing Mac desktop deployments get a concrete data point for deferring upgrades until a patch cycle stabilizes.

Third-order effects

  • If regressions of long-fixed flaws become a pattern across major OS releases, pressure will grow for Apple to treat security patches as test assets that must carry forward between versions, not one-off fixes.
  • As the Mac's profile rises, each Leopard-era defect gets amplified by outlets like The Register within hours, making security quality a standing reputational variable in Apple's release cadence rather than a niche concern.

The trend: Apple's growing market visibility is turning every Leopard security lapse — including reintroduced old bugs — into fast-travelled news that pressures the company's release-and-patch discipline.