CVE-2020-9857

MEDIUM

macOS < 10.15.5 - Unprotected User Data Exposure via URL Parsing Issue

Title source: llm
STIX 2.1

Description

An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.5, Security Update 2020-003 Mojave, Security Update 2020-003 High Sierra. A malicious website may be able to exfiltrate autofilled data in Safari.

References (1)

Core 1
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT211170

Scores

CVSS v3 4.3
EPSS 0.0075
EPSS Percentile 51.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Details

Status published
Products (1)
apple/mac_os_x < 10.15.5
Published Oct 27, 2020
Tracked Since Feb 18, 2026