The vulnerability has been deemed critical and assigned CVSS 5.8 severity rating.
This results in anApplication-side script code executionin the invoice of Apple.
The disclosure timeline is below.
Apple has not yet commented on the issue.
source: www.techworm.net