Logic Issue in Apple Products Exposes Cross-Site Scripting Vulnerability
CVE-2020-9925

6.1MEDIUM

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
16 October 2020

Summary

A logic issue in various Apple products has been identified, which is linked to improper state management. This vulnerability can be exploited through maliciously crafted web content, potentially allowing attackers to execute universal cross-site scripting attacks. Users of affected versions should update their software to mitigate these security risks effectively. The issue has been resolved in the latest updates of affected systems.

Affected Version(s)

iCloud for Windows < unspecified

iCloud for Windows (Legacy) < unspecified

iOS < unspecified

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.