Description
A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.
References (6)
Core 6
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210947
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210918
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210920
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210922
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210923
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210948
Scores
CVSS v3
7.8
EPSS
0.0006
EPSS Percentile
17.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-346
Status
published
Products (9)
apple/icloud
< 7.17
apple/ipados
< 13.3.1
apple/iphone_os
< 13.3.1
apple/itunes
< 12.10.4
apple/safari
< 13.0.5
apple/tvos
< 13.3.1
redhat/enterprise_linux_desktop
7.0
redhat/enterprise_linux_server
7.0
redhat/enterprise_linux_workstation
7.0
Published
Oct 27, 2020
Tracked Since
Feb 18, 2026