Cross-site scripting in Apple iOS - CVE-2019-6229

 

Cross-site scripting in Apple iOS - CVE-2019-6229

Published: January 23, 2019 / Updated: January 29, 2019


Vulnerability identifier: #VU17161
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2019-6229
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists in the WebKit component due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal the authentication cookies and gain access to the device.


Affected software

Apple iOS
Gentoo Linux
tvOS
Opensuse
webkit2gtk (Alpine package)
iCloud for Windows
Apple Safari
iTunes

How to mitigate CVE-2019-6229

Update to version 12.1.3.

Apple iOS - update to 12.1.3 16D39
webkit2gtk (Alpine package) - update to 2.22.7-r0
iCloud for Windows - update to 7.10
Apple Safari - update to 12.0.3
tvOS - update to 12.1.2
iTunes - update to 12.9.3

External References

Related Security Bulletins