Access Issue in Content Security Policy Affecting Apple Products
CVE-2020-9915

6.5MEDIUM

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
16 October 2020

Summary

An issue related to access control was identified within the Content Security Policy implementation across several Apple products. This vulnerability may allow maliciously crafted web content to bypass security restrictions, potentially leading to unauthorized data access. Apple has addressed this issue with improved access restrictions in iOS 13.6, iPadOS 13.6, tvOS 13.4.8, and various other platforms, ensuring enhanced security against these types of attacks.

Affected Version(s)

iCloud for Windows < unspecified

iCloud for Windows (Legacy) < unspecified

iOS < unspecified

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.