The issue was addressed with improved UI handling. This issue is fixed in iOS 12.4, watchOS 5.3. A user may inadvertently complete an in-app purchase while on the lock screen.
References
Link | Resource |
---|---|
https://support.apple.com/HT210346 | Vendor Advisory |
https://support.apple.com/HT210353 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2019-12-18 18:15
Updated : 2019-12-20 19:28
NVD link : CVE-2019-8682
Mitre link : CVE-2019-8682
CVE.ORG link : CVE-2019-8682
JSON object : View
Products Affected
apple
- watchos
- iphone_os
CWE
CWE-306
Missing Authentication for Critical Function