Nitesh Dhanjani released his research on issues within Apple’s Safari browser today.
Apprantly Apple has decided not to fix two of the issues and gave Dhanjani permission to discuss them with the security community.
1. Safari Carpet Bomb. It is possible for a rogue website to litter the user’s Desktop (Windows) or Downloads directory (~/Downloads/ in OSX). [...] ...