PT-2020-20887 · Apple · Safari+2
Imnarendrabhati
+1
·
Published
2020-11-12
·
Updated
2022-06-02
·
CVE-2020-9945
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Safari versions prior to 14.0.1
macOS Big Sur versions prior to 11.0.1
Description
A spoofing issue existed in the handling of URLs, which was addressed with improved input validation. Visiting a malicious website may lead to address bar spoofing.
Recommendations
For Safari versions prior to 14.0.1, update to Safari 14.0.1 to resolve the issue.
For macOS Big Sur versions prior to 11.0.1, update to macOS Big Sur 11.0.1 to resolve the issue.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Safari
Macos Big Sur