A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious website may be able to execute scripts in the context of another website.
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "7.11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "12.9.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "12.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "12.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "12.2"
}
]
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-8503.json"