First published: Wed Sep 12 2018(Updated: )
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
Credit: an anonymous researcher Trend Micro's Zero Day Initiativean anonymous researcher Trend Micro product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/webkit2gtk | <2.22.2-0ubuntu0.18.04.1 | 2.22.2-0ubuntu0.18.04.1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.0 | 2.22.0 |
debian/webkit2gtk | 2.44.2-1~deb11u1 2.44.2-1~deb12u1 2.44.2-1 | |
tvOS | <12 | 12 |
Apple Mobile Safari | <12 | 12 |
Apple iOS, iPadOS, and watchOS | <12 | 12 |
Apple iCloud | <7.7 | 7.7 |
Apple iTunes | <12.9 | 12.9 |
Apple Mobile Safari | <12 | |
iStyle @cosme iPhone OS | <12.0 | |
tvOS | <12 | |
All of | ||
Any of | ||
Apple iCloud for Windows | <7.7 | |
Apple iTunes for Windows | <12.9 | |
Microsoft Windows | ||
Apple iCloud for Windows | <7.7 | |
Apple iTunes for Windows | <12.9 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2018-4309 is a cross-site scripting issue that existed in Safari.
Versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7 are affected.
CVE-2018-4309 was addressed with improved URL validation.
The severity of CVE-2018-4309 is medium with a CVSS score of 6.1.
To fix CVE-2018-4309, you should update to the latest version of Safari, iOS, tvOS, iTunes for Windows, or iCloud for Windows.