Desktop platforms Toolkit
Story: Apple fixes serious OS X flaws
The update does not fix the whole problem, only the auto-execution part (which is obviously the worst) of the weakness demonstrated here:
When users download the sample file and locate it in the Finder, then it still looks like a jpeg unless you happen to check the type in list view or the info panel.
So once you double-click the "jpeg" to open it, actually Terminal will open and execute the sample script. Not good for the average user. Even experienced users do not always explicitly check the type of a file.
OS X should warn after unzipping the archive and on double-clicking the "jpeg".
Full Talkback thread







