First published: Tue May 26 2020(Updated: )
Find My. A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks.
Credit: Zhongcheng Li(CK01) Topsec Alpha Team product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | <10.15.5 | |
Apple macOS Catalina | <10.15.5 | 10.15.5 |
Apple Mojave | ||
Apple High Sierra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-9855 is a vulnerability that existed in the handling of symlinks in Find My.
The severity of CVE-2020-9855 has not been specified.
CVE-2020-9855 affects macOS Catalina 10.15.5 with improved validation of symlinks.
Yes, Apple Mojave is affected by CVE-2020-9855.
To fix CVE-2020-9855, update to the latest version of macOS Catalina as mentioned in Apple's security advisory.