First published: Wed Jul 15 2020(Updated: )
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. A malicious attacker may cause Safari to suggest a password for the wrong domain.
Credit: Nikhil Mittal @c0d3G33k Payatu LabsNikhil Mittal @c0d3G33k Payatu Labs product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <13.1.2 | |
Apple iPadOS | <13.6 | |
Apple iPhone OS | <13.6 | |
Apple iOS | <13.6 | 13.6 |
Apple iPadOS | <13.6 | 13.6 |
Apple Safari | <13.1.2 | 13.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-9903 refers to a logic issue in Safari Login AutoFill that has been addressed with improved restrictions.
The software affected by CVE-2020-9903 include Apple Safari version up to and excluding 13.1.2, Apple iOS version up to and excluding 13.6, and Apple iPadOS version up to and excluding 13.6.
The severity of CVE-2020-9903 is not specifically mentioned.
To fix CVE-2020-9903, it is recommended to update your Apple Safari, Apple iOS, or Apple iPadOS to the specified remedy versions.
You can find more information about CVE-2020-9903 on the official Apple support page: [https://support.apple.com/en-us/HT211292](https://support.apple.com/en-us/HT211292)