First published: Tue Jan 28 2020(Updated: )
A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 13.0.5. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
Credit: product-security@apple.com CodeColorist Ant
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <13.0.5 | |
Apple Safari | <13.0.5 | 13.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-9860 is a vulnerability in Safari that involves a custom URL scheme handling issue that has been addressed with improved input validation.
Apple Safari version up to 13.0.5 is affected by CVE-2020-9860.
To fix CVE-2020-9860, you should update your Apple Safari software to version 13.0.5 or higher.
The severity of CVE-2020-9860 is not mentioned in the provided information.
You can find more information about CVE-2020-9860 on the Apple support website.