Security researcher Robert Swiecki disclosed yesterday another vulnerability within the new Safari 3.0 for Windows beta, bringing the total of public vulnerabilities to nine. The latest flaw allows an attacker to steal a cookie. The flaw exists in the Javascript's window.setTimeout()implementation where the content the timer-triggered function is processed after window.location property is changed.
In response to other Safari 3.0 vulnerabilities, Apple released an updated version that addresses three of the nine public vulnerabilities.