Browser
Authentication & Access Bypass
Safari reader download permission bypass
Safari reader download permission bypass A malicious attacker may be able to change the origin of a frame for a download in Safari Reader mode
3.3
/ 10
Low
CVSS v3.1
ADVISORY ID
PS36
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-9912
VENDORS
Apple
PUBLIC EXPLOIT
None indexed
CWE
PRODUCT
Safari (macOS)
CVSS VECTOR
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
.png)
Summary
Overview
Safari reader download permission bypass
A malicious attacker may be able to change the origin of a frame for a download in Safari Reader mode
Vulnerability details
Vulnerability details
CVE-2020-9912
Low | 3.3
Safari reader download permission bypass A malicious attacker may be able to change the origin of a frame for a download in Safari Reader mode
Impact:
Limited data tampering
DISCLOSURE
Disclosure timeline
2020-04-19 reported to the vendor
2020-07-15 fixed released by the vendor
References
2026-06-17 (NVD record)
Credits
Nikhil Mittal
















