{"id":29782,"date":"2014-07-08T12:32:36","date_gmt":"2014-07-08T19:32:36","guid":{"rendered":"http:\/\/www.intego.com\/mac-security-blog\/?p=29782"},"modified":"2014-07-08T12:32:36","modified_gmt":"2014-07-08T19:32:36","slug":"adobe-flash-player-update-combats-rosetta-flash-attack","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/","title":{"rendered":"Adobe Flash Player Update Combats Rosetta Flash Attack"},"content":{"rendered":"<div id=\"attachment_29824\" style=\"width: 190px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-29824\" class=\"alignright size-full wp-image-29824\" alt=\"Abusing JSONP with Rosetta Flash\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/07\/Rosetta-Flash-attack.png\" width=\"180\" height=\"200\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/07\/Rosetta-Flash-attack.png 180w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2014\/07\/Rosetta-Flash-attack-135x150.png 135w\" sizes=\"auto, (max-width: 180px) 100vw, 180px\" \/><p id=\"caption-attachment-29824\" class=\"wp-caption-text\">Image credit: Michele Spagnuolo<\/p><\/div>\n<p>Adobe Systems has released Adobe Flash Player version 14.0.0.145 for Mac and Windows. Adobe pushed a fix in the Flash Player update that removes a security vulnerability (CVE-2014-4671), which could be used to abuse JSONP endpoints by making a victim perform arbitrary requests to vulnerable domains and expose sensitive data.<\/p>\n<p>Security researcher Michele Spagnuolo disclosed the vulnerability by first notifying affected companies before releasing the code and publishing further details about it.\u00a0On <a title=\"Abusing JSONP with Rosetta Flash\" href=\"http:\/\/miki.it\/blog\/2014\/7\/8\/abusing-jsonp-with-rosetta-flash\/\" target=\"_blank\">his blog<\/a>, Michele explained that\u00a0abusing JSONP endpoints could be done by using Rosetta Flash, &#8220;a tool for converting any SWF file to one composed of only alphanumeric characters in order to abuse JSONP endpoints, making a victim perform arbitrary requests to the domain with the vulnerable endpoint and exfiltrate potentially sensitive data.&#8221;<\/p>\n<p>For those interested in learning more about Rosetta Flash, Michele published a set of <a title=\"Abusing JSONP with Rosetta Flash (PDF)\" href=\"http:\/\/miki.it\/RosettaFlash\/RosettaFlash.pdf\" target=\"_blank\">comprehensive slides (PDF)<\/a>. In the slides, he outlines the Rosetta Flash attack scenario.<\/p>\n<blockquote><p>1. The attacker controls the first bytes of the output of a JSONP API endpoint by specifying the callback parameter in the request.<\/p>\n<p>2. SWF files can be embedded using an &lt;object&gt; tag and will be executed as Flash as long as the content looks like a valid Flash file.<\/p>\n<p style=\"padding-left: 30px;\">&lt;object type=&#8221;application\/x-shockwave-flash&#8221; data=&#8221;<strong>https:\/\/accounts.google.com\/RatePassword?<\/strong><strong>callback=<span style=\"color: #ff0000;\">CWSxx&#8230;<\/span><\/strong>&#8220;&gt;&lt;\/object&gt;<\/p>\n<p>3. Flash can perform GET and POST requests to the hosting domain with the victim&#8217;s cookies and exfiltrate data.<\/p><\/blockquote>\n<p>The security researcher is scheduled to present the vulnerability at <a title=\"HITB2014KUL Conference Speakers\" href=\"https:\/\/conference.hitb.org\/hitbsecconf2014kul\/conference-speakers\/\" target=\"_blank\">Hack In The Box: Malaysia<\/a> in October, and the Rosetta Flash technology will be featured in the next\u00a0<a href=\"http:\/\/openwall.info\/wiki\/people\/solar\/pocorgtfo\" target=\"_blank\">PoC||GTFO<\/a>\u00a0release.<\/p>\n<p>According to Adobe&#8217;s security bulletin (<a title=\"Adobe Security Bulletin (APSB14-17)\" href=\"http:\/\/helpx.adobe.com\/security\/products\/flash-player\/apsb14-17.html\" target=\"_blank\">APSB14-17<\/a>), Adobe Flash Player 14.0.0.145 addresses the following critical vulnerabilities:<\/p>\n<ul>\n<li>These updates include additional validation checks to ensure that Flash Player rejects malicious content from vulnerable JSONP callback APIs (<a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-4671\" target=\"_blank\">CVE-2014-4671<\/a>).<\/li>\n<li>These updates resolve security bypass vulnerabilities (<a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0537\" target=\"_blank\">CVE-2014-0537<\/a>, <a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0539\" target=\"_blank\">CVE-2014-0539<\/a>).<\/li>\n<\/ul>\n<p>Users of Adobe Flash Player 14.0.0.125 and earlier versions for Mac and Windows should update to\u00a0<a title=\"Adobe - Install Adobe Flash Player\" href=\"http:\/\/get.adobe.com\/flashplayer\/\" target=\"_blank\">Adobe Flash Player 14.0.0.145<\/a>\u00a0as soon as possible. Users of Adobe Flash Player 11.2.202.378 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.394.\u00a0Adobe Flash Player 14.0.0.125 installed with Google Chrome will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 14.0.0.145 for Windows, Mac and Linux.\u00a0Users of Adobe AIR 14.0.0.110 and earlier versions should update to\u00a0<a title=\"Adobe - Get Adobe AIR\" href=\"http:\/\/get.adobe.com\/air\/\" target=\"_blank\">Adobe AIR 14.0.0.137<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Adobe Systems has released Adobe Flash Player version 14.0.0.145 for Mac and Windows. Adobe pushed a fix in the Flash Player update that removes a security vulnerability (CVE-2014-4671), which could be used to abuse JSONP endpoints by making a victim perform arbitrary requests to vulnerable domains and expose sensitive data. Security researcher Michele Spagnuolo disclosed [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":9909,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[15,1258,1252,1255],"class_list":["post-29782","post","type-post","status-publish","format-standard","has-post-thumbnail","category-security-news","tag-adobe","tag-adobe-flash-player-14-0-0-145","tag-cve-2014-4671","tag-rosetta-flash"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Adobe Systems has released Adobe Flash Player version 14.0.0.145 for Mac and Windows. Adobe pushed a fix in the Flash Player update that removes a security vulnerability (CVE-2014-4671), which could be used to abuse JSONP endpoints by making a victim perform arbitrary requests to vulnerable domains and expose sensitive data. Security researcher Michele Spagnuolo disclosed\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Derek Erwin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"The Mac Security Blog - Keep Macs safe from the dangers of the Internet\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Adobe Flash Player Update Combats Rosetta Flash Attack\" \/>\n\t\t<meta property=\"og:description\" content=\"Adobe Systems has released Adobe Flash Player version 14.0.0.145 for Mac and Windows. Adobe pushed a fix in the Flash Player update that removes a security vulnerability (CVE-2014-4671), which could be used to abuse JSONP endpoints by making a victim perform arbitrary requests to vulnerable domains and expose sensitive data. Security researcher Michele Spagnuolo disclosed\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2014-07-08T19:32:36+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2014-07-08T19:32:36+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/integogroup\/\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@IntegoSecurity\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Adobe Flash Player Update Combats Rosetta Flash Attack\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Adobe Systems has released Adobe Flash Player version 14.0.0.145 for Mac and Windows. Adobe pushed a fix in the Flash Player update that removes a security vulnerability (CVE-2014-4671), which could be used to abuse JSONP endpoints by making a victim perform arbitrary requests to vulnerable domains and expose sensitive data. Security researcher Michele Spagnuolo disclosed\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@IntegoSecurity\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/adobe-flash-player-update-combats-rosetta-flash-attack\\\/#blogposting\",\"name\":\"Adobe Flash Player Update Combats Rosetta Flash Attack\",\"headline\":\"Adobe Flash Player Update Combats Rosetta Flash Attack\",\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/derek-erwin\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2013\\\/01\\\/Adobe-Security-Update-Tile.png\",\"width\":400,\"height\":260,\"caption\":\"Adobe software security\"},\"datePublished\":\"2014-07-08T12:32:36-07:00\",\"dateModified\":\"2014-07-08T12:32:36-07:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/adobe-flash-player-update-combats-rosetta-flash-attack\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/adobe-flash-player-update-combats-rosetta-flash-attack\\\/#webpage\"},\"articleSection\":\"Security News, Adobe, Adobe Flash Player 14.0.0.145, CVE-2014-4671, Rosetta Flash\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/adobe-flash-player-update-combats-rosetta-flash-attack\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"position\":2,\"name\":\"Security News\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/adobe-flash-player-update-combats-rosetta-flash-attack\\\/#listItem\",\"name\":\"Adobe Flash Player Update Combats Rosetta Flash Attack\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/adobe-flash-player-update-combats-rosetta-flash-attack\\\/#listItem\",\"position\":3,\"name\":\"Adobe Flash Player Update Combats Rosetta Flash Attack\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/logo2.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/adobe-flash-player-update-combats-rosetta-flash-attack\\\/#organizationLogo\",\"width\":122,\"height\":46},\"image\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/adobe-flash-player-update-combats-rosetta-flash-attack\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/integogroup\\\/\",\"https:\\\/\\\/x.com\\\/IntegoSecurity\",\"https:\\\/\\\/www.instagram.com\\\/intego_security\\\/\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/IntegoVideo\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/intego\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/derek-erwin\\\/#author\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/derek-erwin\\\/\",\"name\":\"Derek Erwin\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/adobe-flash-player-update-combats-rosetta-flash-attack\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/badd54c0d1d2f3c4c8497e8a892a5b6cdb00b21e0df10fbea205ab1453e29428?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Derek Erwin\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/adobe-flash-player-update-combats-rosetta-flash-attack\\\/#webpage\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/adobe-flash-player-update-combats-rosetta-flash-attack\\\/\",\"name\":\"Adobe Flash Player Update Combats Rosetta Flash Attack\",\"description\":\"Adobe Systems has released Adobe Flash Player version 14.0.0.145 for Mac and Windows. Adobe pushed a fix in the Flash Player update that removes a security vulnerability (CVE-2014-4671), which could be used to abuse JSONP endpoints by making a victim perform arbitrary requests to vulnerable domains and expose sensitive data. Security researcher Michele Spagnuolo disclosed\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/adobe-flash-player-update-combats-rosetta-flash-attack\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/derek-erwin\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/derek-erwin\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2013\\\/01\\\/Adobe-Security-Update-Tile.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/adobe-flash-player-update-combats-rosetta-flash-attack\\\/#mainImage\",\"width\":400,\"height\":260,\"caption\":\"Adobe software security\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/adobe-flash-player-update-combats-rosetta-flash-attack\\\/#mainImage\"},\"datePublished\":\"2014-07-08T12:32:36-07:00\",\"dateModified\":\"2014-07-08T12:32:36-07:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Adobe Flash Player Update Combats Rosetta Flash Attack<\/title>\n\n","aioseo_head_json":{"title":"Adobe Flash Player Update Combats Rosetta Flash Attack","description":"Adobe Systems has released Adobe Flash Player version 14.0.0.145 for Mac and Windows. Adobe pushed a fix in the Flash Player update that removes a security vulnerability (CVE-2014-4671), which could be used to abuse JSONP endpoints by making a victim perform arbitrary requests to vulnerable domains and expose sensitive data. Security researcher Michele Spagnuolo disclosed","canonical_url":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/#blogposting","name":"Adobe Flash Player Update Combats Rosetta Flash Attack","headline":"Adobe Flash Player Update Combats Rosetta Flash Attack","author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/derek-erwin\/#author"},"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/01\/Adobe-Security-Update-Tile.png","width":400,"height":260,"caption":"Adobe software security"},"datePublished":"2014-07-08T12:32:36-07:00","dateModified":"2014-07-08T12:32:36-07:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/#webpage"},"isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/#webpage"},"articleSection":"Security News, Adobe, Adobe Flash Player 14.0.0.145, CVE-2014-4671, Rosetta Flash"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","position":2,"name":"Security News","item":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/#listItem","name":"Adobe Flash Player Update Combats Rosetta Flash Attack"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/#listItem","position":3,"name":"Adobe Flash Player Update Combats Rosetta Flash Attack","previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}}]},{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","url":"https:\/\/www.intego.com\/mac-security-blog\/","logo":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2026\/08\/logo2.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/#organizationLogo","width":122,"height":46},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/integogroup\/","https:\/\/x.com\/IntegoSecurity","https:\/\/www.instagram.com\/intego_security\/","https:\/\/www.youtube.com\/user\/IntegoVideo","https:\/\/www.linkedin.com\/company\/intego"]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/derek-erwin\/#author","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/derek-erwin\/","name":"Derek Erwin","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/badd54c0d1d2f3c4c8497e8a892a5b6cdb00b21e0df10fbea205ab1453e29428?s=96&d=mm&r=g","width":96,"height":96,"caption":"Derek Erwin"}},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/","name":"Adobe Flash Player Update Combats Rosetta Flash Attack","description":"Adobe Systems has released Adobe Flash Player version 14.0.0.145 for Mac and Windows. Adobe pushed a fix in the Flash Player update that removes a security vulnerability (CVE-2014-4671), which could be used to abuse JSONP endpoints by making a victim perform arbitrary requests to vulnerable domains and expose sensitive data. Security researcher Michele Spagnuolo disclosed","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/#breadcrumblist"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/derek-erwin\/#author"},"creator":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/derek-erwin\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/01\/Adobe-Security-Update-Tile.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/#mainImage","width":400,"height":260,"caption":"Adobe software security"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/#mainImage"},"datePublished":"2014-07-08T12:32:36-07:00","dateModified":"2014-07-08T12:32:36-07:00"},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"The Mac Security Blog - Keep Macs safe from the dangers of the Internet","og:type":"article","og:title":"Adobe Flash Player Update Combats Rosetta Flash Attack","og:description":"Adobe Systems has released Adobe Flash Player version 14.0.0.145 for Mac and Windows. Adobe pushed a fix in the Flash Player update that removes a security vulnerability (CVE-2014-4671), which could be used to abuse JSONP endpoints by making a victim perform arbitrary requests to vulnerable domains and expose sensitive data. Security researcher Michele Spagnuolo disclosed","og:url":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/","article:published_time":"2014-07-08T19:32:36+00:00","article:modified_time":"2014-07-08T19:32:36+00:00","article:publisher":"https:\/\/www.facebook.com\/integogroup\/","twitter:card":"summary_large_image","twitter:site":"@IntegoSecurity","twitter:title":"Adobe Flash Player Update Combats Rosetta Flash Attack","twitter:description":"Adobe Systems has released Adobe Flash Player version 14.0.0.145 for Mac and Windows. Adobe pushed a fix in the Flash Player update that removes a security vulnerability (CVE-2014-4671), which could be used to abuse JSONP endpoints by making a victim perform arbitrary requests to vulnerable domains and expose sensitive data. Security researcher Michele Spagnuolo disclosed","twitter:creator":"@IntegoSecurity"},"aioseo_meta_data":{"post_id":"29782","title":null,"description":null,"keywords":null,"keyphrases":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":null,"twitter_description":null,"schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-09-03 17:56:56","created":"2026-09-03 17:56:56","updated":"2026-09-04 13:39:07","reviewed_by":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/\" title=\"Security News\">Security News<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tAdobe Flash Player Update Combats Rosetta Flash Attack\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.intego.com\/mac-security-blog"},{"label":"Security News","link":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/"},{"label":"Adobe Flash Player Update Combats Rosetta Flash Attack","link":"https:\/\/www.intego.com\/mac-security-blog\/adobe-flash-player-update-combats-rosetta-flash-attack\/"}],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/29782","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=29782"}],"version-history":[{"count":20,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/29782\/revisions"}],"predecessor-version":[{"id":29848,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/29782\/revisions\/29848"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/9909"}],"wp:attachment":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=29782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=29782"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=29782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}