First published: Mon Mar 25 2019(Updated: )
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to universal cross site scripting.
Credit: Ryan Pickren (ryanpickren.com) Ryan Pickren (ryanpickren.com) Ryan Pickren (ryanpickren.com) Ryan Pickren (ryanpickren.com) Ryan Pickren (ryanpickren.com) product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <12.1 | 12.1 |
Apple iCloud for Windows | <7.11 | 7.11 |
Apple iTunes for Windows | <12.9.4 | 12.9.4 |
Apple tvOS | <12.2 | 12.2 |
Apple iOS | <12.2 | 12.2 |
redhat/webkitgtk | <2.24.0 | 2.24.0 |
Apple Icloud Windows | <7.11 | |
Apple Itunes Windows | <12.9.4 | |
Apple Safari | <12.1 | |
Apple iPhone OS | <12.2 | |
Apple tvOS | <12.2 | |
debian/webkit2gtk | 2.44.2-1~deb11u1 2.44.3-1~deb11u1 2.44.2-1~deb12u1 2.46.0-2~deb12u1 2.46.0-2 2.46.1-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8551 is a vulnerability in WebKit that can lead to universal cross-site scripting when processing malicious web content.
iOS versions up to, but excluding, 12.2, tvOS versions up to, but excluding, 12.2, Safari versions up to, but excluding, 12.1, iTunes for Windows versions up to, but excluding, 12.9.4, and iCloud for Windows versions up to, but excluding, 7.11 are affected by CVE-2019-8551.
CVE-2019-8551 has a severity rating of 6.1, which is considered medium.
To fix CVE-2019-8551, update your iOS device to version 12.2 or later, update your tvOS device to version 12.2 or later, update Safari to version 12.1 or later, update iTunes for Windows to version 12.9.4 or later, and update iCloud for Windows to version 7.11 or later.
You can find more information about CVE-2019-8551 in the following references: [Link 1](https://support.apple.com/en-us/HT209599), [Link 2](https://support.apple.com/en-us/HT209601), [Link 3](https://support.apple.com/HT209599)