Browser
Spoofing
Safari Login AutoFill
Safari Login AutoFill A malicious attacker may cause Safari to suggest a password for the wrong domain
7.5
/ 10
High
CVSS v3.1
ADVISORY ID
PS35
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-9903
VENDORS
Apple
PUBLIC EXPLOIT
None indexed
CWE
CWE-346
PRODUCT
Safari (macOS/iOS/iPadOS)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
.png)
Summary
Overview
Safari Login AutoFill
A malicious attacker may cause Safari to suggest a password for the wrong domain
Vulnerability details
Vulnerability details
CVE-2020-9903
CWE-346
High | 7.5
Safari Login AutoFill A malicious attacker may cause Safari to suggest a password for the wrong domain
Auth:
None (remote)
Impact:
Arbitrary data or code modification
DISCLOSURE
Disclosure timeline
2020-03-22 reported to the vendor
2020-07-15 fixed released by the vendor
References
2026-06-17 (NVD record)
Credits
Nikhil Mittal
















