CVE-2020-3888: Medium severity iPadOS vulnerability
Web App. A logic issue was addressed with improved restrictions.
Other sources
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4. A maliciously crafted page may interfere with other web contexts.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Web Appto a version that resolves this vulnerability.Fixed in iOS 13.4 - Upgrade
Upgrade
Web Appto a version that resolves this vulnerability.Fixed in iPadOS 13.4
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9772
- CVE-2020-3917
- CVE-2020-3883
- CVE-2020-9770
- CVE-2020-3913
- CVE-2020-3916
- CVE-2020-9768
- CVE-2020-3919
- CVE-2020-3914
- CVE-2020-9785
- CVE-2020-3910
- CVE-2020-3909
- CVE-2020-3911
- CVE-2020-9780
- CVE-2020-9777
- CVE-2020-3891
- CVE-2020-3890
- CVE-2020-9775
- CVE-2020-9781
- CVE-2020-3918
- CVE-2020-3888
- CVE-2020-9787
- CVE-2020-3894
- CVE-2020-3899
- CVE-2020-3902
- CVE-2020-3895
- CVE-2020-3900
- CVE-2020-3901
- CVE-2020-3887
- CVE-2020-9783
- CVE-2020-3897
- CVE-2020-3885
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-3888.
What is the affected software?
The affected software is Apple iOS versions up to but not including 13.4 and Apple iPadOS versions up to but not including 13.4.
What is the description of this vulnerability?
This vulnerability is a logic issue in a web app that has been addressed with improved restrictions.
How can I fix this vulnerability?
To fix this vulnerability, update your Apple iOS and Apple iPadOS to version 13.4 or later.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Apple support website.