CVE-2013-0962
Description
User-assisted XSS in WebKit on iOS before 6.1 can be triggered via crafted content during a copy-and-paste operation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
User-assisted XSS in WebKit on iOS before 6.1 can be triggered via crafted content during a copy-and-paste operation.
Vulnerability
A cross-site scripting (XSS) vulnerability exists in WebKit, the rendering engine used by Safari and other iOS applications. The issue affects Apple iOS versions prior to 6.1. The vulnerability occurs when crafted content is not properly sanitized during a copy-and-paste operation, allowing arbitrary web script or HTML to be injected into a web page [1].
Exploitation
Exploitation requires user assistance: an attacker must craft malicious content (e.g., a specially formatted web page or document) that, when copied and then pasted by the victim into another context (such as a web form or a browser address bar), triggers the XSS. The attacker would need to convince the user to perform the copy-and-paste operation, for example through social engineering or by embedding the content in a seemingly benign message or webpage [1].
Impact
Successful exploitation allows an attacker to inject malicious scripts in the context of the target web page, leading to potential information disclosure (e.g., cookie theft, session hijacking) or other client-side attacks. The attack runs within the security context of the user's browser session [1].
Mitigation
Apple addressed this issue in iOS 6.1, released on January 28, 2013. Users should update their devices to iOS 6.1 or later through the Settings app (General > Software Update). No workarounds are available [1].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*range: <=6.0.2
- cpe:2.3:o:apple:iphone_os:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:6.0.1:*:*:*:*:*:*:*
- Range: <6.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.