CVE-2020-9916
published 2020-10-16CVE-2020-9916: A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.38%
69.0th percentile
A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker may be able to conceal the destination of a URL.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 7.20 | 7.20 |
| apple | icloud | >= 11.0 < 11.3 | 11.3 |
| apple | icloud_for_windows | >= unspecified < iCloud for Windows 11.3 | iCloud for Windows 11.3 |
| apple | icloud_for_windows | >= unspecified < iCloud for Windows 7.20 | iCloud for Windows 7.20 |
| apple | ios | >= unspecified < iOS 13.6 and iPadOS 13.6 | iOS 13.6 and iPadOS 13.6 |
| apple | ios_13.6_and_ipados | — | — |
| apple | ipados | < 13.6 | 13.6 |
| apple | iphone_os | < 13.6 | 13.6 |
| apple | itunes | < 12.10.8 | 12.10.8 |
| apple | itunes_for_windows | >= unspecified < iTunes 12.10.8 for Windows | iTunes 12.10.8 for Windows |
| apple | safari | < 13.1.2 | 13.1.2 |
| apple | safari | — | — |
| apple | safari | >= unspecified < Safari 13.1.2 | Safari 13.1.2 |
| apple | tvos | < 13.4.8 | 13.4.8 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < tvOS 13.4.8 | tvOS 13.4.8 |
| apple | watchos | < 6.2.8 | 6.2.8 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < watchOS 6.2.8 | watchOS 6.2.8 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xjv7-588c-8c3p: A URL Unicode encoding issue was addressed with improved state management
ghsa_unreviewed·2022-05-24
CVE-2020-9916 [MEDIUM] GHSA-xjv7-588c-8c3p: A URL Unicode encoding issue was addressed with improved state management
A URL Unicode encoding issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker may be able to conceal the destination of a URL.
Apple
CVE-2020-9916: watchOS 6.2.8
vendor_apple·2020-07-15·CVSS 5.3
CVE-2020-9916 [MEDIUM] CVE-2020-9916: watchOS 6.2.8
Apple Security Update: About the security content of watchOS 6.2.8
Product: watchOS
Version: 6.2.8
CVE: CVE-2020-9916
Component: WebKit Page Loading
Impact: A malicious attacker may be able to conceal the destination of a URL
Description: A URL Unicode encoding issue was addressed with improved state management.
Apple
CVE-2020-9916: iOS 13.6 and iPadOS 13.6
vendor_apple·2020-07-15·CVSS 5.3
CVE-2020-9916 [MEDIUM] CVE-2020-9916: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9916
Component: WebKit Page Loading
Impact: A malicious attacker may be able to conceal the destination of a URL
Description: A URL Unicode encoding issue was addressed with improved state management.
Apple
CVE-2020-9916: Safari 13.1.2
vendor_apple·2020-07-15·CVSS 5.3
CVE-2020-9916 [MEDIUM] CVE-2020-9916: Safari 13.1.2
Apple Security Update: About the security content of Safari 13.1.2
Product: Safari
Version: 13.1.2
CVE: CVE-2020-9916
Component: WebKit Page Loading
Impact: A malicious attacker may be able to conceal the destination of a URL
Description: A URL Unicode encoding issue was addressed with improved state management.
Apple
CVE-2020-9916: tvOS 13.4.8
vendor_apple·2020-07-15·CVSS 5.3
CVE-2020-9916 [MEDIUM] CVE-2020-9916: tvOS 13.4.8
Apple Security Update: About the security content of tvOS 13.4.8
Product: tvOS
Version: 13.4.8
CVE: CVE-2020-9916
Component: WebKit Page Loading
Impact: A malicious attacker may be able to conceal the destination of a URL
Description: A URL Unicode encoding issue was addressed with improved state management.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/HT211288https://support.apple.com/HT211290https://support.apple.com/HT211291https://support.apple.com/HT211292https://support.apple.com/HT211293https://support.apple.com/HT211294https://support.apple.com/HT211295https://support.apple.com/HT211288https://support.apple.com/HT211290https://support.apple.com/HT211291https://support.apple.com/HT211292https://support.apple.com/HT211293https://support.apple.com/HT211294https://support.apple.com/HT211295
2020-10-16
Published