CVE-2020-3864

HIGH

iCloud for Windows <7.17 - Info Disclosure

Title source: llm
STIX 2.1

Description

A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.

References (6)

Core 6
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210947
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210918
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210920
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210922
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210923
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210948

Scores

CVSS v3 7.8
EPSS 0.0006
EPSS Percentile 17.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-346
Status published
Products (9)
apple/icloud < 7.17
apple/ipados < 13.3.1
apple/iphone_os < 13.3.1
apple/itunes < 12.10.4
apple/safari < 13.0.5
apple/tvos < 13.3.1
redhat/enterprise_linux_desktop 7.0
redhat/enterprise_linux_server 7.0
redhat/enterprise_linux_workstation 7.0
Published Oct 27, 2020
Tracked Since Feb 18, 2026