PT-2020-11297 · Apple · Apple Macos

Renee Trisberg

·

Published

2020-10-27

·

Updated

2020-10-29

·

CVE-2019-8754

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions macOS versions prior to 10.15.1 Security Update versions prior to 2019-001 Security Update versions prior to 2019-006
Description A cross-origin issue existed with iframe elements, allowing a malicious HTML document to potentially render iframes with sensitive user information. This issue was addressed with improved tracking of security origins.
Recommendations For macOS versions prior to 10.15.1, update to macOS Catalina 10.15.1 or later. For systems requiring Security Update 2019-001 or 2019-006, apply the respective security update. As a temporary workaround, consider restricting the use of iframe elements in HTML documents until the issue is resolved.

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-8754

Affected Products

Apple Macos