CVE-2019-6228 describes a cross-site scripting (XSS) vulnerability in Apple Safari and iOS, stemming from insufficient URL validation. This medium-severity flaw (CVSS 6.1) could allow an unauthenticated attacker to execute arbitrary scripts in a victim's browser by enticing them to process maliciously crafted web content, leading to information disclosure or defacement. While no public exploits, Metasploit modules, or community discussions are reported, users are advised to update to iOS 12.1.3 or Safari 12.0.3 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.0.3CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 12.1.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.