Apple · Safari · CVE-2020-9857
**Name of the Vulnerable Software and Affected Versions**
macOS versions prior to 10.15.5
Security Update versions prior to 2020-003 Mojave
Security Update versions prior to 2020-003 High Sierra
**Description**
The issue existed in the parsing of URLs, which could allow a malicious website to exfiltrate autofilled data in Safari. This was addressed with improved input validation.
**Recommendations**
For macOS versions prior to 10.15.5, update to macOS Catalina 10.15.5.
For Security Update versions prior to 2020-003 Mojave, apply Security Update 2020-003 Mojave.
For Security Update versions prior to 2020-003 High Sierra, apply Security Update 2020-003 High Sierra.