CVE-2020-9802
published 2020-06-09CVE-2020-9802: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes…
PriorityP180high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
8.21%
94.2th percentile
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 7.19 | 7.19 |
| apple | icloud | >= 11.0 < 11.2 | 11.2 |
| apple | icloud_for_windows | >= unspecified < iCloud for Windows 11.2 | iCloud for Windows 11.2 |
| apple | icloud_for_windows | >= unspecified < iCloud for Windows 7.19 | iCloud for Windows 7.19 |
| apple | ios | >= unspecified < iOS 13.5 and iPadOS 13.5 | iOS 13.5 and iPadOS 13.5 |
| apple | ipados | < 13.5 | 13.5 |
| apple | iphone_os | < 13.5 | 13.5 |
| apple | itunes | < 12.10.7 | 12.10.7 |
| apple | itunes_for_windows | >= unspecified < iTunes 12.10.7 for Windows | iTunes 12.10.7 for Windows |
| apple | safari | < 13.1.1 | 13.1.1 |
| apple | safari | >= unspecified < Safari 13.1.1 | Safari 13.1.1 |
| apple | tvos | < 13.4.5 | 13.4.5 |
| apple | tvos | >= unspecified < tvOS 13.4.5 | tvOS 13.4.5 |
| apple | watchos | < 6.2.5 | 6.2.5 |
| apple | watchos | >= unspecified < watchOS 6.2.5 | watchOS 6.2.5 |
| debian | webkit2gtk | < webkit2gtk 2.28.3-1 (bookworm) | webkit2gtk 2.28.3-1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.28.3-1 (bookworm) | webkit2gtk 2.28.3-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- ·Vulnerability affects WebKitGTK before version 2.28.3 and WPE WebKit before 2.28.3; fixed in that release. ↗
- ·Apple platform fixes: iOS/iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2 and 7.19. ↗
- ·Upstream WebKitGTK security advisory WSA-2020-0006 covers this CVE. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
WebKitGTK+ vulnerabilities
vendor_ubuntu·2020-07-14
CVE-2020-13753 WebKitGTK+ vulnerabilities
Title: WebKitGTK+ vulnerabilities
Summary: Several security issues were fixed in WebKitGTK.
A large number of security issues were discovered in the WebKitGTK Web and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of service
attacks, and arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
Red Hat
webkitgtk: Logic issue may lead to arbitrary code execution
vendor_redhat·2020-07-10·CVSS 8.8
CVE-2020-9802 [HIGH] CWE-841 webkitgtk: Logic issue may lead to arbitrary code execution
webkitgtk: Logic issue may lead to arbitrary code execution
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.
A logic issue was found in webkitgtk that affected WebKitGTK versions before 2.28.3 and WPE WebKit versions before 2.28.3. This flaw allows an attacker to process maliciously crafted web content that may lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Out of support scope
Package: we
Debian
CVE-2020-9802: webkit2gtk - A logic issue was addressed with improved restrictions. This issue is fixed in i...
vendor_debian·2020·CVSS 8.8
CVE-2020-9802 [HIGH] CVE-2020-9802: webkit2gtk - A logic issue was addressed with improved restrictions. This issue is fixed in i...
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.28.3-1)
bullseye: resolved (fixed in 2.28.3-1)
forky: resolved (fixed in 2.28.3-1)
sid: resolved (fixed in 2.28.3-1)
trixie: resolved (fixed in 2.28.3-1)
GHSA
GHSA-x2r8-x6h4-39jq: A logic issue was addressed with improved restrictions
ghsa_unreviewed·2022-05-24
CVE-2020-9802 [MEDIUM] GHSA-x2r8-x6h4-39jq: A logic issue was addressed with improved restrictions
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.
Project0
JITSploitation II: Getting Read/Write - Project Zero
project_zero·2020-09-01·CVSS 8.8
CVE-2020-9802 [HIGH] JITSploitation II: Getting Read/Write - Project Zero
Posted by Samuel Groß, Project Zero
This three-part series highlights the technical challenges involved in finding and exploiting JavaScript engine vulnerabilities in modern web browsers and evaluates current exploit mitigation technologies. The exploited vulnerability, CVE-2020-9802, was fixed in iOS 13.5, while two of the mitigation bypasses, CVE-2020-9870 and CVE-2020-9910, were fixed in iOS 13.6.
This is the second part in a series about a Safari renderer exploit from a JIT bug. In Part 1, a vulnerability in the DFG JIT’s implementation of Common-Subexpression Elimination was discussed. The second part starts from the well-known addrof and fakeobj primitives and shows how stable, arbitrary memory read/write can be constructed from it. For that, the StructureID randomization mitiga
Project0
JITSploitation III: Subverting Control Flow - Project Zero
project_zero·2020-09-01·CVSS 8.8
CVE-2020-9802 [HIGH] JITSploitation III: Subverting Control Flow - Project Zero
Posted by Samuel Groß, Project Zero
This three-part series highlights the technical challenges involved in finding and exploiting JavaScript engine vulnerabilities in modern web browsers and evaluates current exploit mitigation technologies. The exploited vulnerability, CVE-2020-9802, was fixed in iOS 13.5, while two of the mitigation bypasses, CVE-2020-9870 and CVE-2020-9910, were fixed in iOS 13.6.
This post is third in a series about a Safari renderer exploit. Part 1 discussed a JIT compiler vulnerability in JSC and Part 2 showed how it could be turned into a reliable read/write primitive despite various mitigations. The purpose of this post is to provide an overview of the various code execution mitigations present in WebKit on iOS 13 and to discuss different approaches for bypas
Project0
JITSploitation I: A JIT Bug - Project Zero
project_zero·2020-09-01·CVSS 8.8
CVE-2020-9802 [HIGH] JITSploitation I: A JIT Bug - Project Zero
By Samuel Groß, Project Zero
This three-part series highlights the technical challenges involved in finding and exploiting JavaScript engine vulnerabilities in modern web browsers and evaluates current exploit mitigation technologies. The exploited vulnerability, CVE-2020-9802, was fixed in iOS 13.5, while two of the mitigation bypasses, CVE-2020-9870 and CVE-2020-9910, were fixed in iOS 13.6.
How might a browser renderer exploit look like in 2020? I set out to answer that question in January this year. Since it’s one of my favorite areas in computer science, I wanted to find a JIT compiler vulnerability, and I was especially interested in trying to find (new) types of vulnerabilities that my fuzzer would have a hard time finding.
As WebKit (on iOS and likely soon on ARM-powered ma
OSV
CVE-2020-9802: A logic issue was addressed with improved restrictions
osv·2020-06-09·CVSS 8.8
CVE-2020-9802 [HIGH] CVE-2020-9802: A logic issue was addressed with improved restrictions
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.
VulnCheck
Apple iOS, iPadOS, tvOS, watchOS, Safari, iTunes for Windows, iCloud for Windows, iCloud for Windows Web Content Vulnerability
vulncheck·2020·CVSS 8.8
CVE-2020-9802 [HIGH] Apple iOS, iPadOS, tvOS, watchOS, Safari, iTunes for Windows, iCloud for Windows, iCloud for Windows Web Content Vulnerability
Apple iOS, iPadOS, tvOS, watchOS, Safari, iTunes for Windows, iCloud for Windows, iCloud for Windows Web Content Vulnerability
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.
Affected: Apple icloud
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.fortinet.com/content/dam/fortinet/assets/threat-reports/threat-landscape-report-2h-2023.pdf; https://www.threatfabric.com/blogs/lightspy-implant-f
No detection rules found.
No public exploits indexed.
arXiv
PatchFuzz: Patch Fuzzing for JavaScript Engines
arxiv_fulltext·2025-05-01
PatchFuzz: Patch Fuzzing for JavaScript Engines
: Patch Fuzzing for JavaScript Engines
Junjie Wang
[email protected]
College of Intelligence and Computing, Tianjin University
China
Yuhan Ma
[email protected]
College of Intelligence and Computing, Tianjin University
China
Xiaofei Xie
[email protected]
Singapore Management University
Singapore
Xiaoning Du
[email protected]
Monash University
Australia
Xiangwei Zhang
[email protected]
College of Intelligence and Computing, Tianjin University
China
## Abstract
Patch fuzzing is a technique aimed at identifying vulnerabilities that arise from newly patched code.
While researchers have made efforts to apply patch fuzzing to testing JavaScript engines with considerable success, these efforts have been limited to using ordinary test cases or publicly available vulner
arXiv
SOK: On the Analysis of Web Browser Security
arxiv_fulltext·2021-12-31
SOK: On the Analysis of Web Browser Security
: On the Analysis of Web Browser Security
fancyplain
Rev.
\ of LastPage
Jungwon Lim*,\;
Yonghwi Jin*^ ,\;
Mansour Alharthi,\;
Xiaokuan Zhang,\;
Jinho Jung,\;
Rajat Gupta,\;
Kuilin Li,\;
Daehee Jang^ ,\;
Taesoo Kim\;
Georgia Institute of Technology ^ Theori Inc. ^ Sungshin Women's University
## Abstract
Web browsers are integral parts of everyone's daily life.
They are commonly used
for security-critical and privacy sensitive tasks,
like banking transactions and checking medical records.
Unfortunately,
modern web browsers are
too complex to be bug free
( , 25 million lines of code in Chrome),
and their role as an interface to the cyberspace
makes them an attractive target for attacks.
Accordingly,
web browsers naturally
become an arena for demonstrating
advanced exploitation techni
Bugzilla
CVE-2020-9802 webkitgtk: Logic issue may lead to arbitrary code execution
bugzilla·2020-09-16·CVSS 8.8
CVE-2020-9802 [HIGH] CVE-2020-9802 webkitgtk: Logic issue may lead to arbitrary code execution
CVE-2020-9802 webkitgtk: Logic issue may lead to arbitrary code execution
A logic issue was found in webkitgtk. Processing maliciously crafted web content may lead to arbitrary code execution. Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before 2.28.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4451 https://access.redhat.com/errata/RHSA-2020:4451
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-9802
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Via RHS
https://support.apple.com/HT211168https://support.apple.com/HT211171https://support.apple.com/HT211175https://support.apple.com/HT211177https://support.apple.com/HT211178https://support.apple.com/HT211179https://support.apple.com/HT211181https://support.apple.com/HT211168https://support.apple.com/HT211171https://support.apple.com/HT211175https://support.apple.com/HT211177https://support.apple.com/HT211178https://support.apple.com/HT211179https://support.apple.com/HT211181
2020-06-09
Published
Exploited in the wild