A weakness in Apple's Safari web browser allows threat actors to leverage the fullscreen browser-in-the-middle (BitM) technique to steal account credentials from unsuspecting users. By abusing the Fullscreen API, which instructs any content on a webpage to enter the browser's fullscreen viewing mode, hackers can exploit the shortcoming to make guardrails less visible on Chromium-based browsers and trick victims into typing sensitive data in an attacker-controlled window. SquareX researchers observed an increase use of this type of malicious activity and say that such attacks are particularly dangerous for Safari users, as Apple’s browser fails to properly alert users when a browser window enters fullscreen mode. “SquareX’s research team has observed multiple instances of the browser’s FullScreen API being exploited to address this flaw by displaying a fullscreen BitM window that covers the parent window’s address bar, as well as a limitation specific to Safari browsers that makes fullscreen BitM attacks especially convincing,” describes the report. A common BitM attack involves tricking users into interacting with an attacker-controlled remote browser that shows a legitimate login page. This is achieved through tools like noVNC - an open-source VNC browser client, which opens a remote browser on top of the victim's session. Since the log in process happens in the attacker's browser, the credentials are collected but the victim also successfully accesses their account unaware...
Apple Safari exposes users to fullscreen browser-in-the-middle attacks
BleepingComputer
·Bill Toulas
·Published May 29, 2025
·Updated
Affected Software
2 affected components
Apple Safari
Apple Safari
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a vulnerability in Apple's Safari browser that allows for fullscreen browser-in-the-middle attacks.
2
What security implications are discussed in the article?
The security implications include the potential for threat actors to steal account credentials from users through this vulnerability.
3
What software is affected by this vulnerability?
The affected software is the Apple Safari web browser.
4
How do attackers exploit this vulnerability in Safari?
Attackers exploit this vulnerability by using the Fullscreen API to create deceptive interfaces that mimic legitimate sites.
5
What should Safari users do to protect themselves from this attack?
Users should be cautious of suspicious fullscreen prompts and ensure they are accessing websites directly rather than through links.