X

How to disable Java in IE, Firefox, Chrome, and Safari

The unpatched Java vulnerability reported last week could be exploited by malware to infect your system, although no such infections have been discovered to date.

Dennis O'Reilly Former CNET contributor
Dennis O'Reilly began writing about workplace technology as an editor for Ziff-Davis' Computer Select, back when CDs were new-fangled, and IBM's PC XT was wowing the crowds at Comdex. He spent more than seven years running PC World's award-winning Here's How section, beginning in 2000. O'Reilly has written about everything from web search to PC security to Microsoft Excel customizations. Along with designing, building, and managing several different web sites, Dennis created the Travel Reference Library, a database of travel guidebook reviews that was converted to the web in 1996 and operated through 2000.
Dennis O'Reilly
3 min read

Last week's notice by researchers at Security Explorations of an unpatched hole in the Java runtime environment may have left you wondering whether to disable Java until Oracle releases a patch. CNET's Topher Kessler noted in his report on the Java flaw that no malware exploiting the vulnerability has yet been documented.

Which leads to the question, "Do I need Java?"

The best way to find out is to disable Java in your browser and re-enable it only if you encounter a site that prompts you to download Java before it will open. Then you can activate the Java plug-in by following the steps below in reverse, and perhaps disable the plug-in again after you leave the site.

(While researching this topic I discovered that one of my test PCs has been browsing flawlessly for more than a year without the Java runtime environment installed.)

These steps will disable Java in Internet Explorer 9, Firefox 15.0.1, Google Chrome 22, and Safari 6.0.1. If you're using an older version of these browsers, update to the latest release. (More information on software updaters is found at the end of this post.)

Disable Java in IE 9 via the 'Manage add-ons' option
Click IE 9's gear icon in the top-right corner of the window and choose "Manage add-ons." Select Toolbars and Extensions in the left pane under Add-on Types and scroll to the entry for the Java plug-in under "Sun Microsystems Inc." Choose the Java entry and click Disable in the bottom-right corner.

Internet Explorer 9 Manage Add-ons window
Disable Java in Internet Explorer 9 by opening Manage Add-ons, selecting the Java entry, and clicking Disable. Screenshot by Dennis O'Reilly/CNET

The next time you start IE, a notice will appear at the bottom of the window informing you that the Java plug-in is ready to use. Click the "Don't enable" button or the x on the right of the pop-up to continue browsing Java-free.

Internet Explore 9 "enable Java" pop-up
After you disable Java in IE you'll be prompted to enable the plug-in the next time you open the browser. Screenshot by Dennis O'Reilly/CNET

Firefox's Java plug-in can be disabled in a jiffy
To prevent the Java plug-in from running in Firefox, click Tools > Add-ons to open the browser's add-on manager. (If you don't see the menu at the top of the Firefox window, press the Alt key.) Choose Plugins in the left pane, scroll to the entry for the Java plug-in, and click its Disable button.

Firefox Add-on Manager's Plugins screen
Disable Firefox's Java plug-in via the browser's Add-on Manager. Screenshot by Dennis O'Reilly/CNET

(When I checked this Firefox setting on one of the PCs in my home office the Java SE 6 plug-in had been disabled automatically because Firefox identified it as vulnerable. Updating to Java SE 7 re-enabled the plug-in in Firefox automatically.)

Turn off Java in Google Chrome
You can disable Java in Chrome by entering "chrome://plugins" in the address bar and pressing Enter to display a list of the browser's plug-ins. Scroll to the entry for Java and click Disable.

Google Chrome list of plug-ins
Click Disable under the entry for Java in Google Chrome's list of plug-ins to prevent the add-on from running automatically. Screenshot by Dennis O'Reilly/CNET

Put Java on the shelf in Safari
To shut down Java in Safari, click Safari > Preferences (or press Command-,), select the Security tab at the top of the window, and uncheck Enable Java.

Safari Preferences dialog Security options
Open Safari's Preferences window and choose the Security tab to disable Java in Apple's browser. Screenshot by Dennis O'Reilly/CNET

A word about drive-by downloads
Every time I write about Java or Adobe's Flash Player, I begin my making sure I have the most recent versions of the plug-ins. And every time I update the two programs manually I'm prompted to download a free security scanner: McAfee Security Scanner for Java and Norton Security Scan for Flash.

It's bad enough that the scans aren't directly related to Java or Flash, but in both instances the option to scan your system is selected by default. People in a hurry will click OK to install the update without realizing they're getting more software than they expect. Unless you want to prolong the update process by adding a malware scan you may not need, be sure to uncheck the scan options whenever you update either plug-in.

Also, the confusion between Java and JavaScript continues unabated. The two technologies are unrelated despite their similar names. While JavaScript poses its own potential security problems, the scripting language is not affected by Java vulnerabilities.

If your browsers and other programs are updated with the latest versions, there's probably no need to disable JavaScript. For more on keeping your software up-to-date, read my review of three free patch-management utilities from May 2011.