Browser

Authentication & Access Bypass

Safari reader download permission bypass

Safari reader download permission bypass A malicious attacker may be able to change the origin of a frame for a download in Safari Reader mode

3.3
/ 10
Low
CVSS v3.1
ADVISORY ID
PS36
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-9912
VENDORS
Apple
PUBLIC EXPLOIT
None indexed
CWE
PRODUCT
Safari (macOS)
CVSS VECTOR
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Safari reader download permission bypass

A malicious attacker may be able to change the origin of a frame for a download in Safari Reader mode

Vulnerability details

Vulnerability details

CVE-2020-9912
Low | 3.3

Safari reader download permission bypass A malicious attacker may be able to change the origin of a frame for a download in Safari Reader mode

Impact:
Limited data tampering
DISCLOSURE

Disclosure timeline

2020-04-19 reported to the vendor

2020-07-15 fixed released by the vendor

Credits

Nikhil Mittal