Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
The new safari 4 still has java enabled by default even though apple still hasn't fixed this. They don't seem to care about security at all.
 
They don't seem to care about security at all.

That is a bit broad and alarmist, don't you think?

How about, "concerning bowser-based java attack vectors, they are exceedingly slow to respond to and correct. "

If they didn't care about this, it would NEVER be patched. Never is a very long time and I think it's unlikely that it will never be patched. They are taking their sweet, sweet time with it though.
 
Ok ok, maybe I went a little overboard on that statement :) but still it's dissapointing, especially when they use security as one of the main selling points of the OS.
 
An unfortunately disconnect between reality, management, and marketing.
Too much focus on new product, not enough focus on maintaining existing products.
 
Java update 4 just showed up in Software Update, mentions improved security, don't know if it fixes this issue
 
Installed the patch, activated Java in my browsers, and tested it at the "Hello World" website listed earlier. Looks like the exploit has been fixed.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.