PT-2020-20758 · Apple · Safari

Ruilin Yang

+1

·

Published

2020-04-01

·

Updated

2020-04-03

·

CVE-2020-9784

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Safari versions prior to 13.1
Description A logic issue was addressed with improved restrictions. A malicious iframe may use another website's download settings.
Recommendations For versions prior to 13.1, update to Safari 13.1 to resolve the issue. As a temporary workaround, consider restricting the use of iframes from untrusted sources until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-9784

Affected Products

Safari