Java Glitch Found

SANTA CLARA, Calif. – Security firm iDefense issued a warning Tuesday that Sun Microsystems' Java Plug-in technology has been identified as having a vulnerability that if exploited could expose a user's network.

The Java Plug-in establishes a connection between popular browsers and the Java platform.

According to Reston, Va.-based iDefense, which roots out malicious code, the vulnerability has been detected in Java 2 Platform, Standard Edition (J2SE) 1.4.2_01 and 1.4.2_04.

The security firm also believes that earlier versions of Java Virtual Machine are vulnerable and that browsers such as Internet Explorer, Mozilla and Firefox on both Windows and Unix platforms could be exploited if they are running a vulnerable JVM.

The vulnerability could provide a gateway for a hacker to bypass the Java sandbox and all security restrictions imposed within Java Applets and provide access to downloading, uploading or executing files within the user's PC, iDefense warned.

"Successful exploitation allows remote attackers to execute hostile Applets that can access files as well as access the network," iDefense stated.

According to the developer's definition, a JVM "mimics" a real Java processor, enabling Java bytecode to be executed as actions or operating system calls on any processor regardless of the operating system.

"A number of private Java packages exist within the JVM and are used internally by the VM," iDefense stated. "Security restrictions prevent applets from accessing these packages. Any attempt to access these packages, results in a thrown exception of 'AccessControlException,' unless the applet is signed and the user has chosen to trust the issuer."

The security firm is recommending that disabling Java or JavaScript will prevent exploitation as the vulnerability relies on the data transfer between the two components.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Luxembourg Media Regulator Fines LiveJasmin for AV Noncompliance

The Luxembourg Independent Audiovisual Authority (ALIA) has levied a fine of 25,000 euros (approximately $28,000) against webcam platform LiveJasmin for failing to comply with provisions of the country’s Electronic Media Law.

AdultHTML Introduces Subscription Option for Website Owners

AdultHTML has added a subscription option for its web development service, allowing site owners to pay a monthly fee for access to developers and tools.

French Parliament Rejects Ban on Purchase of 'Remote' Sexual Services

The French National Assembly has backed off from a proposal to criminalize the purchase, and/or facilitation by online platforms, of sexual services performed remotely by streamers and custom content creators.

2027 XBIZ Exec Awards Pre-Nominations Period Opens

XBIZ is pleased to announce that the pre-nomination period for the 2027 XBIZ Exec Awards, the adult industry’s preeminent career honors, begins Wednesday and runs through Oct. 14.

Takedown Piracy Reports Infiltration, Monitoring of 'Mega.nz' Pirated Content

Takedown Piracy has reported that the organization has successfully infiltrated Mega.nz folders and identified and removed nearly two million instances of stolen content.

Pornhub Unblocks Australia Users on iOS Devices, Citing Apple AV Effectiveness

Pornhub parent company Aylo on Tuesday announced that users in Australia will once again be able to access the popular site if they are using Apple devices and have confirmed their age through Apple’s Australian age-verification process.

California Governor Signs Bill Limiting CIPA Claims

Governor Gavin Newsom has signed into law a bill to narrow the scope of the California Invasion of Privacy Act (CIPA), to prevent abusive lawsuits targeting online businesses, including adult websites.

California Enacts Stricter UGC Rules for Adult Sites

Governor Gavin Newsom has signed into law a bill to impose tighter compliance standards for user-generated content (UGC) on adult websites accessible in California.

Minister: UK Aims to Begin Enforcing 'Choking' Ban Before Year's End

The U.K. will soon begin enforcement of a new law criminalizing depictions of “non-fatal strangulation” in adult content, according to a Ministry of Justice official.

XBIZ LA Conference Website Now Live, Registration Open

The event website for the XBIZ LA conference is now live, offering comprehensive information about the upcoming event, taking place Jan. 7-10 at the JW Marriott L.A. LIVE.

Show More