Mailing the story:
Why Apple must fix Safari 'carpet bombing' flaw immediately
Some quick background: Researcher Nitesh Dhanjani responsibly reports to Apple than it is possible for a malicious Web site to litter the user’s (Windows) Desktop or Downloads directory (~/Downloads/ in OSX) with executables masquerading as legitimate icons.