First published: Wed Sep 12 2018(Updated: )
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
Credit: an anonymous researcher Trend Microan anonymous researcher Trend Micro's Zero Day Initiativean anonymous researcher Trend Microan anonymous researcher Trend Microan anonymous researcher Trend Micro product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <7.7 | 7.7 |
Apple iTunes for Windows | <12.9 | 12.9 |
Apple Safari | <12 | 12 |
Apple tvOS | <12 | 12 |
Apple iOS | <12 | 12 |
Apple Safari | <12 | |
Apple iPhone OS | <12.0 | |
Apple tvOS | <12 | |
All of | ||
Any of | ||
Apple iCloud | <7.7 | |
Apple iTunes | <12.9 | |
Microsoft Windows | ||
Apple iCloud | <7.7 | |
Apple iTunes | <12.9 | |
Microsoft Windows | ||
ubuntu/webkit2gtk | <2.22.2-0ubuntu0.18.04.1 | 2.22.2-0ubuntu0.18.04.1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.2-1ubuntu1 | 2.22.2-1ubuntu1 |
ubuntu/webkit2gtk | <2.22.0 | 2.22.0 |
debian/webkit2gtk | 2.44.2-1~deb11u1 2.44.2-1~deb12u1 2.44.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2018-4309 is a cross-site scripting issue that existed in Safari.
Versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7 are affected.
CVE-2018-4309 was addressed with improved URL validation.
The severity of CVE-2018-4309 is medium with a CVSS score of 6.1.
To fix CVE-2018-4309, you should update to the latest version of Safari, iOS, tvOS, iTunes for Windows, or iCloud for Windows.