CVE-2019-8771UI Misrepresentation / Clickjacking in Apple Safari

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 43.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 24

Description

This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.0.1, iOS 13. Maliciously crafted web content may violate iframe sandboxing policy.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

CVEListV5apple/safariunspecified13.0
NVDapple/safari< 13.0.1
CVEListV5apple/iosunspecified13
NVDapple/iphone_os< 13.0.

🔴Vulnerability Details

4
GHSA
GHSA-w6pm-jp6h-x3pq: This issue was addressed with improved iframe sandbox enforcement2022-05-24
CVEList
CVE-2019-8771: This issue was addressed with improved iframe sandbox enforcement2020-10-27
OSV
CVE-2019-8771: This issue was addressed with improved iframe sandbox enforcement2020-10-27
VulnCheck
Apple safari Improper Restriction of Rendered UI Layers or Frames2019

📋Vendor Advisories

5
Ubuntu
WebKitGTK+ vulnerabilities2019-11-07
Red Hat
webkitgtk: Violation of iframe sandboxing policy2019-10-29
Apple
CVE-2019-8771: Safari 13.0.12019-09-24
Apple
CVE-2019-8771: iOS 132019-09-19
Debian
CVE-2019-8771: webkit2gtk - This issue was addressed with improved iframe sandbox enforcement. This issue is...2019

💬Community

1
Bugzilla
CVE-2019-8771 webkitgtk: Violation of iframe sandboxing policy2020-09-07
CVE-2019-8771 — UI Misrepresentation / Clickjacking | cvebase