VulnerabilityModified
CVE-2019-8670
Visiting a malicious website may lead to address bar spoofing.
MEDIUM 4.3EPSS 0.92%
Does this matter?
Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.
Description
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.6, Safari 12.1.2. Visiting a malicious website may lead to address bar spoofing.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apple/safari · apple/mac os x
- Source
- product-security@apple.com
References
- https://support.apple.com/HT210348Vendor Advisory
- https://support.apple.com/HT210355Vendor Advisory
- https://support.apple.com/HT210348Vendor Advisory
- https://support.apple.com/HT210355Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.