First published: Wed Sep 16 2020(Updated: )
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A malicious application may be able to determine a user's open tabs in Safari.
Credit: Josh Parnham @joshparnham Josh Parnham @joshparnham product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | <14.2 | |
Apple iPhone OS | <14.2 | |
Apple Mac OS X | <11.0.1 | |
Apple iOS | <14.0 | 14.0 |
Apple iPadOS | <14.0 | 14.0 |
Apple macOS Big Sur | <11.0.1 | 11.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2020-9977.
The affected software for CVE-2020-9977 includes Apple iOS 14.0, Apple iPadOS 14.0, and Apple macOS Big Sur 11.0.1.
The impact of CVE-2020-9977 is a validation issue in the entitlement verification process, which could potentially be exploited by attackers.
To fix CVE-2020-9977, update your Apple device to the latest available version of Apple iOS, Apple iPadOS, or Apple macOS Big Sur.
You can find more information about CVE-2020-9977 on the Apple support website.