A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. A malicious attacker may cause Safari to suggest a password for the wrong domain.
The product does not properly verify that the source of data or communication is valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Safari | Apple | * | 13.1.2 (excluding) |
Ipados | Apple | * | 13.6 (excluding) |
Iphone_os | Apple | * | 13.6 (excluding) |