Safari prior to version 4 may permit an evil web page to steal files from the local system.
Full techinical details – http://scary.beasts.org/security/CESA-2009-006.html
Blogpost – http://scarybeastsecurity.blogspot.com/2009/06/apples-safari-4-fixes-local-file-theft.html
(includes 1-click demos)


