A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
https://support.apple.com/kb/HT209141 | vendor advisory |
https://support.apple.com/kb/HT209140 | vendor advisory |
https://support.apple.com/kb/HT209106 | vendor advisory |
https://support.apple.com/kb/HT209108 | vendor advisory |
https://support.apple.com/kb/HT209109 | vendor advisory |