First published: Mon Mar 25 2019(Updated: )
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting.
Credit: Ryan Pickren (ryanpickren.com) Ryan Pickren (ryanpickren.com) Ryan Pickren (ryanpickren.com) Ryan Pickren (ryanpickren.com) product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <12.1 | |
Apple iPhone OS | <12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8505 is a vulnerability in Safari Reader that allows universal cross-site scripting through a maliciously crafted webpage.
CVE-2019-8505 has a severity level of medium (6.1).
CVE-2019-8505 could potentially allow an attacker to execute arbitrary code on your device if they can get you to visit a maliciously crafted webpage.
To fix CVE-2019-8505, make sure your iOS and Safari are updated to version 12.2 or later.
You can find more information about CVE-2019-8505 on the Apple support page.