Vulnerability record · CVE-2011-3230 · published 14 October 2011
CVE-2011-3230: Apple Safari file: URL policy bypass allows code execution
Apple · Safari
Apple Safari before 5.1.1 on Mac OS X fails to enforce an intended policy for file: URLs. A crafted website can abuse this to run arbitrary code on the victim's machine. The flaw is a permissions/access-control weakness in how Safari handles local file references.
Description
Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via a crafted web site.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
medium priorityCVSS 2.0 base score is 6.8 (MEDIUM) with partial confidentiality, integrity and availability impact, and there is no confirmed exploitation despite a high EPSS score.
What it is
Apple Safari before 5.1.1 on Mac OS X fails to enforce an intended policy for file: URLs. A crafted website can abuse this to run arbitrary code on the victim's machine. The flaw is a permissions/access-control weakness in how Safari handles local file references.
Impact
An attacker who lures a user to a malicious site can execute arbitrary code with the privileges of the Safari process, potentially leading to full compromise of the user's account and data.
Attack surface
Reached over the network via a crafted web site viewed in Safari; no authentication is required, but the CVSS vector (AV:N/AC:M/Au:N) indicates some user interaction or a non-trivial condition is needed to trigger it.
Exploitation
Not listed in CISA KEV and no public exploit or exploitation tag appears in the references; EPSS is high (0.493, 98.8th percentile), suggesting elevated predicted likelihood, but the record provides no confirmed in-the-wild activity.
What to do
- Upgrade Safari to 5.1.1 or later on affected Mac OS X systems (Apple advisory HT5000).
- If immediate upgrade is not possible, restrict browsing to trusted sites and avoid untrusted links that may invoke file: URL handling.
- Enforce browser hardening and disable or restrict local file access where policy allows.
- Monitor vendor advisories for any backported fixes on supported OS versions.
Detection
- Review Safari version inventory to identify hosts still running versions before 5.1.1.
- Monitor endpoint logs for Safari spawning unexpected child processes or accessing unusual file: paths.
- Watch for suspicious outbound browsing patterns or downloads preceding local file execution on macOS endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-3230 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-3230), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.