New Java 7 exploit can potentially affect Macs
While there are no known attempts to use a newly discovered vulnerability to target Mac users, the exploit has been successfully triggered in both Safari and Firefox on Macs running Mountain Lion. — A new vulnerability was found last week in the latest Java 7 runtime from Oracle.
Context & Ripple Effects
The April 2012 Flashback trojan outbreak already established that Java — not OS X itself — was the soft spot on Macs, infecting hundreds of thousands of machines through an unpatched runtime before Apple pushed a fix for 600,000 affected Macs. That episode ended with the framing AllThingsD offered at the time: not a Mac virus, but a weakness in Java.
This new disclosure extends that pattern to Oracle's current Java 7 runtime: researchers have confirmed the exploit fires in both Safari and Firefox on Macs running Mountain Lion, and the story's spread across BGR, Computerworld, The Next Web, MacRumors and a US-CERT advisory shows how quickly a proof-of-concept on one platform now travels once Java is the vector.
First-order effects
- Mac users with the Java 7 browser plugin enabled are exposed to a confirmed-working exploit even on fully updated Mountain Lion systems, though no attacks targeting Macs were known as of the disclosure.
- Oracle faces immediate pressure to ship an out-of-band Java 7 patch, since the flaw sits in its latest runtime rather than in Apple's legacy Java distribution.
Second-order effects
- Apple's post-Flashback posture of decoupling and quickly disabling Java versions it ships becomes the de facto containment lever again, putting Apple and Oracle's patch cadences in direct tension over who protects Mac users.
- Security teams and IT administrators, already burned by Flashback, face renewed decisions about disabling Java in browsers outright — a cost borne by enterprises relying on Java applets.
Third-order effects
- If every new Java 7 flaw reopens the Mac attack surface regardless of OS X patching, the 'Macs don't get malware' assumption erodes further and platform security debates shift from operating systems to third-party runtimes and browser plugins.
- Repeated cross-platform Java incidents strengthen the case for browsers and OS vendors shipping kill-switch defaults for plugin content, marginalizing applet-based Java on the client entirely.
The trend: Java's browser plugin is consolidating as a recurring, platform-agnostic attack vector, with Oracle's patch cadence — not Apple's or Microsoft's — setting the security clock for desktop users.