CVE-2019-8649: XSS
A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site scripting.
Other sources
WebKit. A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management.
WebKitGTK Security Advisory WSA-2019-0004 describes the following issue:
CVE-2019-8649
Processing maliciously crafted web content may lead to universal cross site scripting. A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management.
Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before 2.24.3.
— Red Hat
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-9506
- CVE-2020-10135
- CVE-2019-8646
- CVE-2019-8647
- CVE-2019-8660
- CVE-2019-8702
- CVE-2018-16860
- CVE-2019-8668
- CVE-2019-13118
- CVE-2019-8698
- CVE-2019-8662
- CVE-2019-8657
- CVE-2019-8690
- CVE-2019-8649
- CVE-2019-8658
- CVE-2019-8644
- CVE-2019-8666
- CVE-2019-8669
- CVE-2019-8671
- CVE-2019-8672
- CVE-2019-8673
- CVE-2019-8676
- CVE-2019-8677
- CVE-2019-8678
- CVE-2019-8679
- CVE-2019-8680
- CVE-2019-8681
- CVE-2019-8683
- CVE-2019-8684
- CVE-2019-8685
- CVE-2019-8686
- CVE-2019-8687
- CVE-2019-8688
- CVE-2019-8689
- CVE-2019-8693
- CVE-2019-8656
- CVE-2018-19860
- CVE-2019-8661
- CVE-2019-8675
- CVE-2019-8696
- CVE-2019-8539
- CVE-2019-8697
- CVE-2019-8648
- CVE-2019-8663
- CVE-2019-8695
- CVE-2019-8691
- CVE-2019-8692
- CVE-2019-8694
- CVE-2019-8670
- CVE-2019-8701
- CVE-2019-8667
- CVE-2019-8665
- CVE-2019-8699
- CVE-2019-8682
Frequently Asked Questions
What is the severity of CVE-2019-8649?
The severity of CVE-2019-8649 is medium with a CVSS score of 6.1.
Which software versions are affected by CVE-2019-8649?
The affected software versions include iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, and iCloud for Windows 10.6.
How was CVE-2019-8649 fixed?
CVE-2019-8649 was fixed with improved state management in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, and iCloud for Windows 10.6.
What is the Common Weakness Enumeration (CWE) for CVE-2019-8649?
The Common Weakness Enumeration (CWE) for CVE-2019-8649 is CWE-79.
Where can I find more information about CVE-2019-8649?
You can find more information about CVE-2019-8649 on the Apple support website.