First published: Tue Oct 30 2018(Updated: )
Safari Reader. A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation.
Credit: Ryan Pickren (ryanpickren.com) Ryan Pickren (ryanpickren.com) Ryan Pickren (ryanpickren.com) Ryan Pickren (ryanpickren.com) Ryan Pickren (ryanpickren.com) product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <12.0.1 | 12.0.1 |
Apple iOS, iPadOS, and watchOS | <12.1 | 12.1 |
Apple iOS, iPadOS, and watchOS | <5.1 | 5.1 |
Apple iCloud | <7.8 | 7.8 |
Apple iTunes | <12.9.1 | 12.9.1 |
Apple Mobile Safari | <12.0.1 | |
iStyle @cosme iPhone OS | <12.1 | |
Apple iOS, iPadOS, and watchOS | <5.1 | |
Apple iCloud for Windows | <7.8 | |
Apple iTunes for Windows | <12.9.1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4377 is a cross-site scripting vulnerability that existed in Safari.
Versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, and iCloud for Windows 7.8 are affected by CVE-2018-4377.
The severity of CVE-2018-4377 is medium with a score of 6.1.
To fix CVE-2018-4377, update to iOS 12.1 or later, watchOS 5.1 or later, Safari 12.0.1 or later, iTunes 12.9.1 or later, and iCloud for Windows 7.8 or later.
You can find more information about CVE-2018-4377 at the following references: [Link 1](https://support.apple.com/kb/HT209192), [Link 2](https://support.apple.com/kb/HT209195), [Link 3](https://support.apple.com/kb/HT209196).