A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1. A malicious iframe may use another website’s download settings.
No PoCs from references.
- https://github.com/houjingyi233/macOS-iOS-system-security