CVE-2019-8505: Apple iPhone OS

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. Enabling the Safari Reader feature on a maliciously crafted webpage may lead to universal cross site scripting.

Affected products

  • Apple iPhone OS: before 12.2 (fixed in 12.2)
  • Apple Safari: before 12.1 (fixed in 12.1)

Published 2019-12-18. Last modified 2026-06-17.