/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researcher shows flaw to spoof URLs in Safari and Edge while visiting a malicious link; weeks after disclosure, Microsoft has patched the flaw, but Apple hasn't

Egghead says Apple has yet to patch spoofing vulnerability  —  A security researcher has disclosed a flaw that could be used …

The Register Shaun Nichols

Context & Ripple Effects

This is at least the third time Safari's address bar has been shown to lie to users: researchers found an address-spoofing bug in iOS and OS X Safari back in 2015, and again in 2020 across Safari, Opera, and Yandex. What distinguishes this disclosure is the split verdict — Microsoft shipped an Edge fix within weeks while Apple left Safari exposed, echoing the [[a:966767|WebKit remote-code-execution flaw that sat unpatched for weeks despite an available open-source fix]].

The asymmetry matters because both browsers were vulnerable to the same researcher-reported flaw, so patch speed — not vulnerability discovery — is what separates the vendors here.

First-order effects

  • Safari users who click a malicious link remain exposed to URL spoofing that can mask the true destination, while Edge users are protected by Microsoft's patch.
  • Apple now carries the reputational cost of being the laggard vendor on a publicly disclosed flaw, with Egghead's disclosure live and unremediated.

Second-order effects

  • Researchers gain leverage from the contrast: a same-flaw, two-vendor comparison makes Apple's patch latency measurable and publishable, raising the pressure on future disclosures.
  • Enterprises weighing Safari against Chromium-based browsers get fresh evidence that Microsoft's patch pipeline responds faster to third-party reports, feeding into browser policy decisions.

Third-order effects

  • If the pattern holds — repeated Safari spoofing findings plus slow WebKit fixes — Apple's security response cadence becomes a standing differentiator in the browser market rather than a one-off embarrassment.
  • Public disclosure followed by vendor-by-vendor patch races hardens into the norm for browser flaws, making time-to-patch the metric researchers and buyers track instead of mere vulnerability counts.

The trend: Browser security is shifting from who finds flaws to who fixes them fastest, with Apple's WebKit patch latency emerging as a recurring weak point against Microsoft's faster Edge response.