First published: Thu Sep 19 2019(Updated: )
A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.
Credit: Sergei Glazunov Google Project ZeroSergei Glazunov Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <13 | |
Apple iPhone OS | <13.0 | |
WebKitGTK WebKitGTK | <2.26.4 | |
redhat/webkitgtk | <2.24.4 | 2.24.4 |
Apple Safari | <13 | 13 |
Apple iOS | <13 | 13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2019-8674 is medium.
CVE-2019-8674 affects Apple Safari versions up to and excluding 13, allowing for universal cross-site scripting when processing malicious web content.
CVE-2019-8674 affects Apple iPhone OS versions up to and excluding 13.0, allowing for universal cross-site scripting when processing malicious web content.
CVE-2019-8674 affects WebKitGTK WebKitGTK versions up to and excluding 2.26.4, allowing for universal cross-site scripting when processing malicious web content.
CVE-2019-8674 is fixed in Apple Safari 13, so updating to the latest version will resolve the vulnerability.
CVE-2019-8674 is fixed in Apple iPhone OS 13.0, so updating to the latest version will resolve the vulnerability.
To fix CVE-2019-8674 in WebKitGTK WebKitGTK, update to version 2.26.4 or later.