:

MAC FREEZE VULNERABILITY DISCOVERED IN WEB BROWSERS

DEV DESK1 MIN READ
FRI, SEP 11, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A security researcher has identified a method for untrusted websites to freeze macOS systems, dubbed "The Deathray." The technique exploits browser behavior to render machines unresponsive.

Security researcher Auberon detailed the vulnerability on their blog, explaining how malicious websites can trigger a freeze state on Mac computers. The attack leverages browser resource consumption patterns to overwhelm system processes. The findings have generated significant discussion in the developer community, with 75 comments on Hacker News and 120 upvotes, indicating widespread interest among security professionals. The vulnerability affects standard web browsing behavior, meaning users visiting a compromised or malicious site could experience system freezes without additional prerequisites. This differs from traditional exploits requiring user interaction beyond normal browsing. The discovery highlights ongoing security challenges in web browser design and macOS system resource management. Browser vendors and Apple may need to implement additional safeguards to prevent resource exhaustion attacks. The full technical details are available at auberon.xyz, where the researcher provides an in-depth analysis of the vulnerability mechanism and potential mitigation strategies.

■ SOURCES

Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Hardware wallet maker Trezor confirmed a data breach affecting its email provider, exposing hundreds of thousands of crypto owners to targeted scams. This marks the second breach involving a third-party service that Trezor depends on.

1H AGOAI Desk

A US judge dismissed two lawsuits against LinkedIn for scanning users' browser extensions, ruling that downloading extensions constitutes voluntary data exposure. The Microsoft subsidiary prevailed on its motion to dismiss.

2H AGOAI Desk

Florida's Department of Highway Safety and Motor Vehicles confirmed a breach of its DAVID driver database after attackers exploited stolen credentials from a police department employee.

3H AGOSecurity Desk

Threat actors are chaining critical vulnerabilities in JFrog Artifactory to bypass authentication and deploy Rust-based backdoors on self-hosted servers. The attacks grant attackers administrative privileges on vulnerable instances.

5H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.