CVE-2019-8753 is a cross-site scripting (XSS) vulnerability affecting Apple's macOS, watchOS, iOS, and tvOS. This medium-severity flaw (CVSS 6.1) could allow an unauthenticated attacker to execute arbitrary scripts in a user's browser by tricking them into processing maliciously crafted web content, potentially leading to information disclosure or unauthorized actions. While no active exploitation, public exploit code, or significant community discussion has been observed, Apple addressed this issue with improved checks in macOS Catalina 10.15, watchOS 6, iOS 13, and tvOS 13.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.15CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 13CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 6.0CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.