PT-2020-20812 · Apple · Safari

Codecolorist

·

Published

2020-10-27

·

Updated

2024-02-21

·

CVE-2020-9860

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Safari versions prior to 13.0.5
Description A custom URL scheme handling issue was addressed with improved input validation. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
Recommendations For versions prior to 13.0.5, update to Safari 13.0.5 to resolve the issue. As a temporary workaround, consider avoiding the use of custom URL schemes until the update is applied.

Fix

Related Identifiers

CVE-2020-9860

Affected Products

Safari