Risk: High
Three critical vulnerabilities have been brought to light in Apple's recent security update, which can result in a buffer overflow, execution of malicious files and in some instances, JavaScript bypassing same-origin policies.
A boundary error in Mail can cause a buffer overflow by double clicking on a specially crafted AppleDouble attachment.
One of the flaws was found in Safari and can cause a malicious application to appear to be safe. If a user opens this "safe" attachment, it could direct them to a malicious website, enabling automatic malicious code execution.
The updates to fix these flaws are available from Apple's website, www.apple.com/support/downloads