The bad news is that these flaws, including CVE-2008-5353 and a few other security problems, were fixed by Sun more than six months ago.
These flaws were serious, and could enable attackers to use especially crafted Java applets to run code of their choice on targeted system. Several weeks ago, Mac developer Landon Fuller described the flaws as "trivially exploitable" and published proof-of-concept code to prove the severity of the condition.
InformationWeek's Tom Claburn reported on this issue today:
In May, Intego, which makes security software for Macs, warned Mac users to disable Java in their Web browsers until Apple got around to fixing the Java vulnerability."Apple has been aware of this vulnerability for at least five months, since it was made public, but has neglected to issue a security update to protect against this issue," Intego said in a security advisory last month.
More information from Apple on today's updates is available from Apple's support site.
My question: If Sun could fix these flaws seven months ago, why did it take Apple so long to get to it?
If you'd like my mobile security and technology observations, follow me on Twitter.