NA

CVE-2019-8670

Vulnerability Summary

Apple Safari could allow a remote malicious user to conduct spoofing attacks, caused by an inconsistent user interface issue. By persuading a victim to visit a specially-crafted Web site, an attacker could exploit this vulnerability to spoof the address bar.

Vulnerability Trend

Vendor Advisories

About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security updates page Apple security documents reference vulnerabilities by CVE-ID when possible ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security updates page Apple security documents reference vulnerabilities by CVE-ID when possible ...

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2019-7-22-3 Safari 1212 Safari 1212 is now available and addresses the following: Safari Available for: macOS Sierra 10126, macOS High Sierra 10136, and included in macOS Mojave 10146 Impact: Visiting a malicious website may lead to address bar spoofing Description: An inconsiste ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2019-7-22-2 macOS Mojave 10146, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra macOS Mojave 10146, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra are now available and address the following: AppleGraphicsControl Available for: macOS Mojave ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2019-7-22-3 Safari 1212 Safari 1212 is now available and addresses the following: Safari Available for: macOS Sierra 10126, macOS High Sierra 10136, and included in macOS Mojave 10146 Impact: Visiting a malicious website may lead to address bar spoofing Description: An inconsiste ...

Recent Articles

It's 2019 and you can still pwn an iPhone with a website: Apple patches up iOS, Mac bugs in July security hole dump
The Register • Shaun Nichols in San Francisco • 23 Jul 2019

20 WebKit flaws among latest batch of bug fixes

On Monday Apple released a fresh round of security fixes for a load of its operating systems and applications.
The July patch batch addresses vulnerabilities in iOS, MacOS, Safari, watchOS, and tvOS, though many of the updates are for common components across each of the platforms, such as the WebKit browser engine.
For iOS, the 12.4 update brings a total of 37 fixes for various components in the mobile operating system.
More than half of those CVE-listed flaws were found in We...