CVE-2020-9784: Medium severity Safari vulnerability
A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1. A malicious iframe may use another website’s download settings.
Other sources
Safari Downloads. A logic issue was addressed with improved restrictions.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 13.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-9784?
CVE-2020-9784 is a vulnerability in Safari Downloads that allows for a logic issue to occur due to insufficient restrictions.
What software is affected by CVE-2020-9784?
Safari version up to but excluding 13.1 is affected by CVE-2020-9784.
How does CVE-2020-9784 affect Safari Downloads?
CVE-2020-9784 addresses a logic issue in Safari Downloads with improved restrictions to prevent exploitation.
What is the severity of CVE-2020-9784?
The severity of CVE-2020-9784 is not provided in the information.
How can I fix CVE-2020-9784?
To fix CVE-2020-9784, update Safari to version 13.1 or later as per the remedy provided by Apple.