CVE-2019-8674: Apple iPhone OS
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.
Affected products
- Apple iPhone OS: before 13.0 (fixed in 13.0)
- Apple Safari: before 13 (fixed in 13)
- WebKitGTK WebKitGTK: before 2.26.4 (fixed in 2.26.4)
Published 2019-12-18. Last modified 2026-06-17.