CVE-2020-9993UI Misrepresentation / Clickjacking in Apple IOS AND Ipados

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 51.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 8
Latest updateMay 24

Description

The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Visiting a malicious website may lead to address bar spoofing.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages7 packages

CVEListV5apple/safariunspecified14.0
NVDapple/ipados< 14.0
CVEListV5apple/watchosunspecified7.0
NVDapple/watchos< 7.0
CVEListV5apple/ios_and_ipadosunspecified14.0

🔴Vulnerability Details

2
GHSA
GHSA-f6p3-gc9f-3r6w: The issue was addressed with improved UI handling2022-05-24
CVEList
CVE-2020-9993: The issue was addressed with improved UI handling2020-12-08

📋Vendor Advisories

1
Apple
CVE-2020-9993: watchOS 7.02020-09-16
CVE-2020-9993 — UI Misrepresentation / Clickjacking | cvebase