Apple on Friday released patches for a cross-site scripting (XSS) flaw in WebCore and a vulnerability in WebKit that allows arbitrary code execution — as well a third beta version of Safari for Windows.