CVE-2020-9894: Input Validation
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
Other sources
An out-of-bounds read was found in webkitgtk. A remote attacker may be able to cause unexpected application termination or arbitrary code execution. Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before 2.28.4.
— Red Hat
WebKit. An out-of-bounds read was addressed with improved input validation.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9884
- CVE-2020-9889
- CVE-2020-9888
- CVE-2020-9890
- CVE-2020-9891
- CVE-2020-9907
- CVE-2020-9883
- CVE-2020-9865
- CVE-2020-9900
- CVE-2020-9980
- CVE-2020-9933
- CVE-2020-9914
- CVE-2020-27933
- CVE-2020-11758
- CVE-2020-11759
- CVE-2020-11760
- CVE-2020-11761
- CVE-2020-11762
- CVE-2020-11763
- CVE-2020-11764
- CVE-2020-11765
- CVE-2020-9871
- CVE-2020-9872
- CVE-2020-9874
- CVE-2020-9879
- CVE-2020-9936
- CVE-2020-9937
- CVE-2020-9919
- CVE-2020-9876
- CVE-2020-9873
- CVE-2020-9938
- CVE-2020-9984
- CVE-2020-9877
- CVE-2020-9875
- CVE-2019-14899
- CVE-2020-9909
- CVE-2020-9904
- CVE-2020-9863
- CVE-2020-9892
- CVE-2020-9902
- CVE-2020-9905
- CVE-2020-9926
- CVE-2020-9880
- CVE-2020-9878
- CVE-2020-9940
- CVE-2020-9868
- CVE-2020-9901
- CVE-2020-9894
- CVE-2020-9915
- CVE-2020-9925
- CVE-2020-9893
- CVE-2020-9895
- CVE-2020-9910
- CVE-2020-9916
- CVE-2020-9862
- CVE-2020-6514
- CVE-2020-9918
- CVE-2020-9923
- CVE-2020-9997
- CVE-2020-9920
- CVE-2020-9885
- CVE-2020-9881
- CVE-2020-9882
- CVE-2020-9985
- CVE-2020-9906
- CVE-2020-9942
- CVE-2020-9912
- CVE-2020-9903
- CVE-2020-9911
- CVE-2020-9931
- CVE-2020-9934
- CVE-2019-19906
- CVE-2020-9898
- CVE-2020-9917
Frequently Asked Questions
What is CVE-2020-9894?
CVE-2020-9894 is a vulnerability in WebKit that allows for an out-of-bounds read due to improved input validation.
What software is affected by CVE-2020-9894?
Apple Safari 13.1.2, Apple iOS up to version 13.6, Apple iPadOS up to version 13.6, Apple watchOS up to version 6.2.8, Apple iCloud for Windows up to version 7.20, Apple iTunes for Windows up to version 12.10.8, and Apple tvOS up to version 13.4.8 are affected by CVE-2020-9894.
How can I fix CVE-2020-9894?
To fix CVE-2020-9894, update your software to the latest version provided by Apple.
What is the severity of CVE-2020-9894?
The severity of CVE-2020-9894 is not mentioned in the provided information.
Where can I find more information about CVE-2020-9894?
You can find more information about CVE-2020-9894 on the official Apple support page: [https://support.apple.com/en-us/HT211295](https://support.apple.com/en-us/HT211295)