CVE-2020-3864: High severity tvos vulnerability
A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.
Other sources
WebKit Page Loading. A logic issue was addressed with improved validation.
WebKitGTK Security Advisory WSA-2020-0002 describes the following issue:
CVE-2020-3864
Impact: A DOM object context may not have had a unique security origin. Description: A logic issue was addressed with improved validation.
Versions affected: WebKitGTK before 2.26.4 and WPE WebKit before 2.26.4.
— Red Hat
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-3857
- CVE-2020-3855
- CVE-2020-3826
- CVE-2020-3870
- CVE-2020-3878
- CVE-2020-3880
- CVE-2020-3837
- CVE-2019-8836
- CVE-2020-3840
- CVE-2020-3875
- CVE-2020-3872
- CVE-2020-3836
- CVE-2020-3842
- CVE-2020-3853
- CVE-2020-3846
- CVE-2020-3856
- CVE-2020-3829
- CVE-2020-3825
- CVE-2020-3868
- CVE-2020-3862
- CVE-2020-3867
- CVE-2020-3865
- CVE-2020-3864
- CVE-2020-3838
- CVE-2019-8827
- CVE-2020-3861
- CVE-2020-9860
- CVE-2020-3833
- CVE-2020-3852
- CVE-2020-3841
- CVE-2020-3869
- CVE-2020-3858
- CVE-2020-3831
- CVE-2020-3860
- CVE-2020-3873
- CVE-2020-3859
- CVE-2020-3844
- CVE-2020-3828
- CVE-2020-3874
- CVE-2020-3843
Frequently Asked Questions
What is CVE-2020-3864?
CVE-2020-3864 is a vulnerability in WebKit Page Loading that is caused by a logic issue.
Which software products are affected by CVE-2020-3864?
The affected software products include Apple Safari 13.0.5, Apple tvOS 13.3.1, Apple iCloud for Windows 10.9.2, Apple iTunes for Windows 12.10.4, Apple iCloud for Windows 7.17, Apple iOS 13.3.1, and Apple iPadOS 13.3.1.
How can I fix CVE-2020-3864?
To fix CVE-2020-3864, make sure you update your software to the latest version provided by Apple.
Where can I find more information about CVE-2020-3864?
You can find more information about CVE-2020-3864 on the Apple support website.
What is the severity of CVE-2020-3864?
The severity of CVE-2020-3864 is not specified.