A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 13.0.5. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
2020-10-27T21:15:15.570
2024-11-21T05:41:25.513
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9