A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. A malicious attacker may cause Safari to suggest a password for the wrong domain.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
https://support.apple.com/HT211288 | vendor advisory |
https://support.apple.com/HT211292 | vendor advisory |