Researcher shows flaw to spoof URLs in Safari and Edge while visiting a malicious link; weeks after disclosure, Microsoft has patched the flaw, but Apple hasn't
Egghead says Apple has yet to patch spoofing vulnerability — A security researcher has disclosed a flaw that could be used …
Context & Ripple Effects
This is at least the third time Safari's address bar has been shown to lie to users: researchers found an address-spoofing bug in iOS and OS X Safari back in 2015, and again in 2020 across Safari, Opera, and Yandex. What distinguishes this disclosure is the split verdict — Microsoft shipped an Edge fix within weeks while Apple left Safari exposed, echoing the [[a:966767|WebKit remote-code-execution flaw that sat unpatched for weeks despite an available open-source fix]].
The asymmetry matters because both browsers were vulnerable to the same researcher-reported flaw, so patch speed — not vulnerability discovery — is what separates the vendors here.
First-order effects
- Safari users who click a malicious link remain exposed to URL spoofing that can mask the true destination, while Edge users are protected by Microsoft's patch.
- Apple now carries the reputational cost of being the laggard vendor on a publicly disclosed flaw, with Egghead's disclosure live and unremediated.
Second-order effects
- Researchers gain leverage from the contrast: a same-flaw, two-vendor comparison makes Apple's patch latency measurable and publishable, raising the pressure on future disclosures.
- Enterprises weighing Safari against Chromium-based browsers get fresh evidence that Microsoft's patch pipeline responds faster to third-party reports, feeding into browser policy decisions.
Third-order effects
- If the pattern holds — repeated Safari spoofing findings plus slow WebKit fixes — Apple's security response cadence becomes a standing differentiator in the browser market rather than a one-off embarrassment.
- Public disclosure followed by vendor-by-vendor patch races hardens into the norm for browser flaws, making time-to-patch the metric researchers and buyers track instead of mere vulnerability counts.
The trend: Browser security is shifting from who finds flaws to who fixes them fastest, with Apple's WebKit patch latency emerging as a recurring weak point against Microsoft's faster Edge response.