CVE-2020-9993
published 2020-12-08CVE-2020-9993: The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Visiting a malicious website may…
PriorityP418medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
1.10%
61.9th percentile
The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Visiting a malicious website may lead to address bar spoofing.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | >= unspecified < 14.0 | 14.0 |
| apple | ipados | < 14.0 | 14.0 |
| apple | iphone_os | < 14.0 | 14.0 |
| apple | safari | — | — |
| apple | safari | >= unspecified < 14.0 | 14.0 |
| apple | watchos | < 7.0 | 7.0 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 7.0 | 7.0 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2020-9993: watchOS 7.0
vendor_apple·2020-09-16·CVSS 4.3
CVE-2020-9993 [MEDIUM] CVE-2020-9993: watchOS 7.0
Apple Security Update: About the security content of watchOS 7.0
Product: watchOS
Version: 7.0
CVE: CVE-2020-9993
Component: Safari
Impact: Visiting a malicious website may lead to address bar spoofing
Description: The issue was addressed with improved UI handling.
GHSA
GHSA-f6p3-gc9f-3r6w: The issue was addressed with improved UI handling
ghsa_unreviewed·2022-05-24
CVE-2020-9993 [MEDIUM] CWE-1021 GHSA-f6p3-gc9f-3r6w: The issue was addressed with improved UI handling
The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Visiting a malicious website may lead to address bar spoofing.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-08
Published