Oracle Releases Patch to Address Security Vulnerability in Java 7 - MacRumors
Skip to Content

Oracle Releases Patch to Address Security Vulnerability in Java 7

Java Web 165Earlier this week, we reported on a newly-disclosed vulnerability in Java SE 7 that could pose a risk for users on a wide variety of platforms, including OS X. While the real-world threat to Mac users stemming from the vulnerability is very low given that a Mac-specific exploit for the vulnerability has not been seen and only a small fraction of Mac users have manually installed Java SE 7, the incident has served as another reminder the Mac users can be vulnerable malicious attacks.

Although Oracle was reportedly warned of the issue months ago and apparently did not take significant action to protect users until it became public, the company has now moved quickly to address the problem with today's announcement regarding the release of Java SE 7 Update 7. The release addresses the specific vulnerability disclosed earlier this week as well as several others, and the company has also released Java SE 6 Update 35 to address a separate issue with the earlier version.

If successfully exploited, these vulnerabilities can provide a malicious attacker the ability to plant discretionary binaries onto the compromised system, e.g. the vulnerabilities can be exploited to install malware, including Trojans, onto the targeted system. Note that this malware may in some instances be detected by current antivirus signatures upon its installation.

The updated versions of Java are available though Oracle's Java download page.

Popular Stories

iOS 26

iOS 26.4 Adds Two New Features to CarPlay

Tuesday March 24, 2026 1:55 pm PDT by
iOS 26.4 was released today, and it includes a couple of new features for CarPlay: an Ambient Music widget and support for voice-based chatbot apps. To update your iPhone 11 or newer to iOS 26.4, open the Settings app and tap on General → Software Update. CarPlay will automatically offer the new features so long as the iPhone connected to your vehicle is running iOS 26.4 or later....
Apple Business hero

Apple Unveils 'Apple Business' All-in-One Platform

Tuesday March 24, 2026 8:53 am PDT by
Apple today announced Apple Business, a new all-in-one platform that unifies device management, productivity tools, and customer outreach features. The service is designed to be a consolidated replacement for several of Apple's existing business-focused offerings, including Apple Business Essentials, Apple Business Manager, and Apple Business Connect. It provides organizations with a single...
AirPods Pro Firmware Feature

Apple Releases New Firmware for AirPods Pro 3, AirPods Pro 2 and AirPods 4

Tuesday March 24, 2026 12:31 pm PDT by
Apple today released new firmware for the AirPods Pro 2, AirPods Pro 3, and the AirPods 4. The firmware has a version number of 8B39, up from 8B34 on the AirPods Pro 3, 8B28 on the AirPods Pro 2, and 8B21 on the AirPods 4. There is no word on what's included in the firmware, but Apple has a support document with limited notes. Most updates are limited to bug fixes and performance...

Top Rated Comments

Rodimus Prime Avatar
177 months ago
plugging up the sinking ship, sad really - java comes in quite handy, i'm guessing it will eventually phased out from the apple environment.
sounds like someone who has no understanding of Java or how powerful it really is.
Score: 8 Votes (Like | Disagree)
bbeagle Avatar
177 months ago
So.... that means that we will get it in about a month and a half when Apple releases it?

You haven't been paying attention. Apple is not releasing any Java updates ever again. They all go through Oracle now.
Score: 8 Votes (Like | Disagree)
669532 Avatar
177 months ago
plugging up the sinking ship, sad really - java comes in quite handy, i'm guessing it will eventually phased out from the apple environment.
Score: 4 Votes (Like | Disagree)
177 months ago
plugging up the sinking ship, sad really - java comes in quite handy, i'm guessing it will eventually phased out from the apple environment.

Which is ironic, because Java has built-in protection against buffer overflows whereas C, C++, and Objective-C (Cocoa) are all vulnerable. While clunky (though it's gotten better) and ugly, Java was always a pretty safe environment.
Score: 3 Votes (Like | Disagree)
177 months ago
plugging up the sinking ship, sad really - java comes in quite handy, i'm guessing it will eventually phased out from the apple environment.

Sounds just like Flash...
Score: 2 Votes (Like | Disagree)
GJSchaller Avatar
177 months ago
The Mac version of the Oracle release will update it self if you launch the control panel (from System Preferences) - mine just asked me to update when I looked at it.
Score: 2 Votes (Like | Disagree)