CVE-2020-20095: Medium severity apple imessage vulnerability
Published Mar 23, 2022
·Updated
iMessage (Messages app) iOS 12.4 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.
Affected Software
1 affected component
Apple Imessage Iphone Os<=12.4
Event History
Mar 23, 2022
CVE Published
via MITRE·09:28 PM
Data Sourced
via MITRE·09:28 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this iMessage vulnerability?
The vulnerability ID for this iMessage vulnerability is CVE-2020-20095.
2
What is the severity of CVE-2020-20095?
The severity of CVE-2020-20095 is medium with a CVSS score of 6.5.
3
Which version of iOS is affected by CVE-2020-20095?
iOS 12.4 and prior versions are affected by CVE-2020-20095.
4
What is the impact of CVE-2020-20095?
CVE-2020-20095 allows URI spoofing via specially crafted messages, resulting in potential phishing attacks.
5
Are there any known fixes for CVE-2020-20095?
Currently, there are no known fixes for CVE-2020-20095. It is recommended to exercise caution when interacting with URI messages in iMessage.