Browser

Authentication & Access Bypass

Safari reader same origin policy (SOP) bypass

Safari reader same origin policy (SOP) bypass An issue in Safari Reader mode may allow a remote attacker to bypass the Same Origin Policy

7.5
/ 10
High
CVSS v3.1
ADVISORY ID
PS37
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-9911
VENDORS
Apple
PUBLIC EXPLOIT
None indexed
CWE
PRODUCT
Safari (macOS/iOS/iPadOS)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Safari reader same origin policy (SOP) bypass

An issue in Safari Reader mode may allow a remote attacker to bypass the Same Origin Policy

Vulnerability details

Vulnerability details

CVE-2020-9911
High | 7.5

Safari reader same origin policy (SOP) bypass An issue in Safari Reader mode may allow a remote attacker to bypass the Same Origin Policy

Impact:
Arbitrary data or code modification
DISCLOSURE

Disclosure timeline

2020-04-19 reported to the vendor

2020-07-15 fixed released by the vendor

Credits

Nikhil Mittal