First published: Wed Jul 15 2020(Updated: )
WebKit. An out-of-bounds read was addressed with improved input validation.
Credit: 0011 Trend Micro Zero Day Initiative0011 Trend Micro Zero Day Initiative0011 Trend Micro Zero Day Initiative0011 Trend Micro Zero Day Initiative0011 Trend Micro Zero Day Initiative0011 Trend Micro Zero Day Initiative0011 Trend Micro Zero Day Initiative0011 Trend Micro Zero Day Initiative0011 Trend Micro Zero Day Initiative product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/webkitgtk | <2.28.4 | 2.28.4 |
tvOS | <13.4.8 | 13.4.8 |
Apple iOS, iPadOS, and watchOS | <6.2.8 | 6.2.8 |
Apple iCloud | <11.3 | 11.3 |
Apple iCloud | <7.20 | 7.20 |
iTunes | <12.10.8 | 12.10.8 |
Safari | <13.1.2 | 13.1.2 |
Apple iOS and iPadOS | <13.6 | 13.6 |
Apple iOS, iPadOS, and macOS | <13.6 | 13.6 |
iCloud for Windows | <7.20 | |
iCloud for Windows | >=11.0<11.3 | |
iTunes | <12.10.8 | |
Safari | <13.1.2 | |
Apple iOS, iPadOS, and macOS | <13.6 | |
iPhone OS | <13.6 | |
tvOS | <13.4.8 | |
Apple iOS, iPadOS, and watchOS | <6.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2020-9894 is a vulnerability in WebKit that allows for an out-of-bounds read due to improved input validation.
Apple Safari 13.1.2, Apple iOS up to version 13.6, Apple iPadOS up to version 13.6, Apple watchOS up to version 6.2.8, Apple iCloud for Windows up to version 7.20, Apple iTunes for Windows up to version 12.10.8, and Apple tvOS up to version 13.4.8 are affected by CVE-2020-9894.
To fix CVE-2020-9894, update your software to the latest version provided by Apple.
The severity of CVE-2020-9894 is not mentioned in the provided information.
You can find more information about CVE-2020-9894 on the official Apple support page: [https://support.apple.com/en-us/HT211295](https://support.apple.com/en-us/HT211295)