Browser

Spoofing

Safari Login AutoFill

Safari Login AutoFill A malicious attacker may cause Safari to suggest a password for the wrong domain

7.5
/ 10
High
CVSS v3.1
ADVISORY ID
PS35
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-9903
VENDORS
Apple
PUBLIC EXPLOIT
None indexed
CWE
CWE-346
PRODUCT
Safari (macOS/iOS/iPadOS)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Safari Login AutoFill

A malicious attacker may cause Safari to suggest a password for the wrong domain

Vulnerability details

Vulnerability details

CVE-2020-9903
CWE-346
High | 7.5

Safari Login AutoFill A malicious attacker may cause Safari to suggest a password for the wrong domain

Auth:
None (remote)
Impact:
Arbitrary data or code modification
DISCLOSURE

Disclosure timeline

2020-03-22 reported to the vendor

2020-07-15 fixed released by the vendor

Credits

Nikhil Mittal