Squarex says hackers can abuse the full screen API in Safari to trick people into running remote browsers
Browser-in-the-mid-Midten attacks are good at stealing login credentials
Apple says protection frames are in place and will not pursue it further
FullScreen API, a functionality of the Apple Safari browser, which allows web developers to present specific elements in full -screen mode, has a vulnerability abused in convincing password theft, experts have warned.
Security researchers Squarex claim to have observed an increase in use in this type of attack that utilizes the browser-in-mid (BITM) technique.