First published: Mon Mar 25 2019(Updated: )
WebKit. A logic issue was addressed with improved validation.
Credit: Linus Särud DetectifyLinus Särud DetectifyLinus Särud DetectifyLinus Särud DetectifyLinus Särud Detectify product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <12.1 | 12.1 |
Apple iCloud for Windows | <7.11 | 7.11 |
Apple iTunes for Windows | <12.9.4 | 12.9.4 |
Apple tvOS | <12.2 | 12.2 |
Apple iOS | <12.2 | 12.2 |
Apple Icloud Windows | <7.11 | |
Apple Itunes Windows | <12.9.4 | |
Apple Safari | <12.1 | |
Apple iPhone OS | <12.2 | |
Apple tvOS | <12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8503 is a logic issue in WebKit that allows a malicious website to execute scripts in the context of another website.
iOS versions up to but not including 12.2, tvOS versions up to but not including 12.2, Safari versions up to but not including 12.1, iTunes version 12.9.4 for Windows, and iCloud version 7.11 for Windows.
CVE-2019-8503 has a severity rating of 8.8 (Critical).
To fix CVE-2019-8503, you need to update to the latest versions of the affected software: iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, and iCloud 7.11 for Windows.
You can find more information about CVE-2019-8503 on the Apple support page: [link](https://support.apple.com/en-us/HT209599).