First published: Wed Jul 15 2020(Updated: )
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. An issue in Safari Reader mode may allow a remote attacker to bypass the Same Origin Policy.
Credit: Nikhil Mittal @c0d3G33k Payatu LabsNikhil Mittal @c0d3G33k Payatu Labs product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <13.1.2 | |
Apple iPadOS | <13.6 | |
Apple iPhone OS | <13.6 | |
Apple iOS | <13.6 | 13.6 |
Apple iPadOS | <13.6 | 13.6 |
Apple Safari | <13.1.2 | 13.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-9911 is a vulnerability in Safari Reader that was addressed with improved restrictions.
CVE-2020-9911 affects Apple Safari versions up to and excluding 13.1.2, Apple iOS versions up to and excluding 13.6, and Apple iPadOS versions up to and excluding 13.6.
The severity of CVE-2020-9911 has not been specified.
To fix CVE-2020-9911, update your Apple Safari, iOS, and iPadOS to version 13.1.2, 13.6, or newer.
You can find more information about CVE-2020-9911 on Apple's support page at https://support.apple.com/en-us/HT211292 and https://support.apple.com/en-us/HT211288.