First published: Mon Jul 22 2019(Updated: )
A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site scripting.
Credit: Sergei Glazunov Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/webkitgtk | <2.24.4 | 2.24.4 |
tvOS | <12.4 | 12.4 |
macOS Mojave | <10.14.6 | 10.14.6 |
macOS High Sierra | ||
macOS High Sierra | ||
Apple iOS, iPadOS, and watchOS | <12.4 | 12.4 |
Apple iCloud | <7.13 | 7.13 |
Apple iCloud | <10.6 | 10.6 |
iTunes | <12.9.6 | 12.9.6 |
iCloud for Windows | <7.13 | |
iCloud for Windows | >=10.0<10.6 | |
iTunes | <12.9.6 | |
Apple Mobile Safari | <12.1.2 | |
iStyle @cosme iPhone OS | <12.4 | |
Apple iOS and macOS | <10.14.6 | |
tvOS | <12.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The severity of CVE-2019-8649 is medium with a CVSS score of 6.1.
The affected software versions include iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, and iCloud for Windows 10.6.
CVE-2019-8649 was fixed with improved state management in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, and iCloud for Windows 10.6.
The Common Weakness Enumeration (CWE) for CVE-2019-8649 is CWE-79.
You can find more information about CVE-2019-8649 on the Apple support website.