CVE-2020-3887: Medium severity Apple This document describes the security content of tvOS vulnerability
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A download's origin may be incorrectly associated.
Other sources
WebKit. A logic issue was addressed with improved restrictions.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple iCloudto a version that resolves this vulnerability.Fixed in 10.9.3 - Upgrade
Upgrade
Apple iCloudto a version that resolves this vulnerability.Fixed in 7.18 - Upgrade
Upgrade
iTunesto a version that resolves this vulnerability.Fixed in 12.10.5 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 13.1 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple iOS/iPadOS/tvOS and related softwareto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple Safari (WebKit)to a version that resolves this vulnerability.Fixed in 13.1 - Upgrade
Upgrade
iTunes for Windowsto a version that resolves this vulnerability.Fixed in 12.10.5 - Upgrade
Upgrade
iCloud for Windowsto a version that resolves this vulnerability.Fixed in 10.9.3 - Upgrade
Upgrade
iCloud for Windowsto a version that resolves this vulnerability.Fixed in 7.18
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9772
- CVE-2020-3917
- CVE-2020-3883
- CVE-2020-9768
- CVE-2020-3919
- CVE-2020-3914
- CVE-2020-9785
- CVE-2020-3909
- CVE-2020-3911
- CVE-2020-3910
- CVE-2020-3918
- CVE-2020-9787
- CVE-2020-3895
- CVE-2020-3900
- CVE-2020-3894
- CVE-2020-3899
- CVE-2020-3902
- CVE-2020-3901
- CVE-2020-3887
- CVE-2020-9783
- CVE-2020-3897
- CVE-2020-3885
- CVE-2020-9784
- CVE-2020-9770
- CVE-2020-3913
- CVE-2020-3916
- CVE-2020-9780
- CVE-2020-9777
- CVE-2020-3891
- CVE-2020-3890
- CVE-2020-9775
- CVE-2020-9781
- CVE-2020-3888
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2020-3887.
Which software versions are affected by this vulnerability?
tvOS 13.4, Safari 13.1, iOS 13.4, iPadOS 13.4, iCloud for Windows 10.9.3, iCloud for Windows 7.18, and iTunes for Windows 12.10.5 are affected.
What is the severity level of this vulnerability?
The severity level of this vulnerability is not mentioned.
What is the fix for this vulnerability?
Apple has addressed the vulnerability with improved restrictions. It is recommended to update to the latest software versions mentioned in the affected software section to mitigate the risk.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the official Apple support page. Here are some references: [1](https://support.apple.com/en-us/HT211104), [2](https://support.apple.com/en-us/HT211102), [3](https://support.apple.com/en-us/HT211101)