CVE-2019-8654Improper Input Validation in Apple Safari

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 51.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 18
Latest updateMay 24

Description

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.1. Visiting a malicious website may lead to user interface spoofing.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5apple/safariunspecifiedSafari 13.0.1
NVDapple/safari< 13.0.1

🔴Vulnerability Details

2
GHSA
GHSA-rm5x-36q2-9xmp: An inconsistent user interface issue was addressed with improved state management2022-05-24
CVEList
CVE-2019-8654: An inconsistent user interface issue was addressed with improved state management2019-12-18

📋Vendor Advisories

1
Apple
CVE-2019-8654: Safari 13.0.12019-09-24
CVE-2019-8654 — Improper Input Validation in Apple | cvebase