This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15, watchOS 6, iOS 13, tvOS 13. Processing maliciously crafted web content may lead to a cross site scripting attack.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT210634 | vendor advisory |
https://support.apple.com/en-us/HT210604 | vendor advisory |
https://support.apple.com/en-us/HT210606 | vendor advisory |
https://support.apple.com/en-us/HT210607 | vendor advisory |