VYPR
Unrated severityNVD Advisory· Published Jan 29, 2013· Updated Apr 29, 2026

CVE-2013-0962

CVE-2013-0962

Description

User-assisted XSS in WebKit on iOS before 6.1 can be triggered via crafted content during a copy-and-paste operation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

User-assisted XSS in WebKit on iOS before 6.1 can be triggered via crafted content during a copy-and-paste operation.

Vulnerability

A cross-site scripting (XSS) vulnerability exists in WebKit, the rendering engine used by Safari and other iOS applications. The issue affects Apple iOS versions prior to 6.1. The vulnerability occurs when crafted content is not properly sanitized during a copy-and-paste operation, allowing arbitrary web script or HTML to be injected into a web page [1].

Exploitation

Exploitation requires user assistance: an attacker must craft malicious content (e.g., a specially formatted web page or document) that, when copied and then pasted by the victim into another context (such as a web form or a browser address bar), triggers the XSS. The attacker would need to convince the user to perform the copy-and-paste operation, for example through social engineering or by embedding the content in a seemingly benign message or webpage [1].

Impact

Successful exploitation allows an attacker to inject malicious scripts in the context of the target web page, leading to potential information disclosure (e.g., cookie theft, session hijacking) or other client-side attacks. The attack runs within the security context of the user's browser session [1].

Mitigation

Apple addressed this issue in iOS 6.1, released on January 28, 2013. Users should update their devices to iOS 6.1 or later through the Settings app (General > Software Update). No workarounds are available [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*range: <=6.0.2
    • cpe:2.3:o:apple:iphone_os:6.0:*:*:*:*:*:*:*
    • cpe:2.3:o:apple:iphone_os:6.0.1:*:*:*:*:*:*:*
  • Apple Inc./iOSllm-fuzzy
    Range: <6.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.