Apple's Mac app store serves up out-dated software

'JoshMeister' says that the Mac app store – a feature added to the Mac OS X v10.6 Snow Leopard and built into the upcoming v10.7 Lion operating system – may be putting their computer's security at risk.

An example of this, he says, is where Opera Software recently released v11.11 of its software, which fixed a critical flaw.

"Mac users who have downloaded Opera through the app store may find themselves using a copy of Opera that is now two versions old, 11.01, which was released back in March and is vulnerable to the security bug patched in 11.11", he says in his security blog.

"Users who rely on the app store to tell them whether their software is up-to-date may not be aware of the security risks and may continue to use an unsafe version of the Opera browser", he adds.

The researcher claims he has notified Apple and Opera about the issue and an Opera representative acknowledged that: "We are waiting for the App store to approve the next version of Opera for Mac. For now the only solution is to go to www.opera.com/download."

But Opera, he says, is not the only app that is out-dated. The current version of Amazon's Kindle app is 1.5.1, while the version in the App Store is still 1.2.3, which was released in January.

"Amazon does not publicly disclose its changelog, so there is no easy way to know whether any security issues exist in Kindle for Mac version 1.2.3", he said.

According to Joshmeister, in the past, Apple has come under fire for taking unreasonable amounts of time – sometimes weeks or even months – to approve both new apps and app updates in its iOS App Store.

"It remains to be seen how quickly Apple will approve the latest Opera update in the Mac App Store", he said.

The good news, however, is that if you discover an app that has been downloaded from the Mac app store is out-dated, you can drag the out-dated app from your Applications folder into the trash.

And then, he asserts, you can drag the current version of the application from the developer's website into the applications folder.

What’s hot on Infosecurity Magazine?