CVE-2019-8753Cross-site Scripting in Apple Macos

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 37.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 24

Description

This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15, watchOS 6, iOS 13, tvOS 13. Processing maliciously crafted web content may lead to a cross site scripting attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages8 packages

CVEListV5apple/tvosunspecified13
NVDapple/tvos< 13
CVEListV5apple/macosunspecified10.15
CVEListV5apple/watchosunspecified6
NVDapple/watchos< 6.0

🔴Vulnerability Details

2
GHSA
GHSA-4x46-qwv4-rmhx: This issue was addressed with improved checks2022-05-24
CVEList
CVE-2019-8753: This issue was addressed with improved checks2020-10-27

📋Vendor Advisories

4
Apple
CVE-2019-8753: macOS Catalina 10.152019-10-07
Apple
CVE-2019-8753: tvOS 132019-09-24
Apple
CVE-2019-8753: watchOS 62019-09-19
Apple
CVE-2019-8753: iOS 132019-09-19
CVE-2019-8753 — Cross-site Scripting in Apple Macos | cvebase