First published: Mon Mar 25 2019(Updated: )
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting.
Credit: Ryan Pickren (ryanpickren.com) Ryan Pickren (ryanpickren.com) Ryan Pickren (ryanpickren.com) Ryan Pickren (ryanpickren.com) product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <12.1 | |
Apple iPhone OS | <12.2 | |
Apple Safari | <12.1 | 12.1 |
Apple iOS | <12.2 | 12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-6204 is a logic issue in Safari Reader that has been fixed in iOS 12.2 and Safari 12.1.
Enabling Safari Reader on a maliciously crafted webpage may lead to universal cross-site scripting on iOS versions up to but excluding 12.2.
Update your iOS device to version 12.2 or later to fix CVE-2019-6204.
CVE-2019-6204 affects Safari 12.1. Update to the latest version of Safari to fix the vulnerability.
CVE-2019-6204 has a severity rating of 6.1 (Medium).