CVE-2020-9915: Medium severity tvos vulnerability
An access issue existed in Content Security Policy. Processing maliciously crafted web content may prevent Content Security Policy from being enforced. Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before 2.28.4.
Other sources
An access issue existed in Content Security Policy. This issue was addressed with improved access restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
— MITRE
WebKit. An access issue existed in Content Security Policy. This issue was addressed with improved access restrictions.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9884
- CVE-2020-9889
- CVE-2020-9888
- CVE-2020-9890
- CVE-2020-9891
- CVE-2020-9907
- CVE-2020-9883
- CVE-2020-9865
- CVE-2020-9900
- CVE-2020-9980
- CVE-2020-9933
- CVE-2020-9914
- CVE-2020-27933
- CVE-2020-11758
- CVE-2020-11759
- CVE-2020-11760
- CVE-2020-11761
- CVE-2020-11762
- CVE-2020-11763
- CVE-2020-11764
- CVE-2020-11765
- CVE-2020-9871
- CVE-2020-9872
- CVE-2020-9874
- CVE-2020-9879
- CVE-2020-9936
- CVE-2020-9937
- CVE-2020-9919
- CVE-2020-9876
- CVE-2020-9873
- CVE-2020-9938
- CVE-2020-9984
- CVE-2020-9877
- CVE-2020-9875
- CVE-2019-14899
- CVE-2020-9909
- CVE-2020-9904
- CVE-2020-9863
- CVE-2020-9892
- CVE-2020-9902
- CVE-2020-9905
- CVE-2020-9926
- CVE-2020-9880
- CVE-2020-9878
- CVE-2020-9940
- CVE-2020-9868
- CVE-2020-9901
- CVE-2020-9894
- CVE-2020-9915
- CVE-2020-9925
- CVE-2020-9893
- CVE-2020-9895
- CVE-2020-9910
- CVE-2020-9916
- CVE-2020-9862
- CVE-2020-6514
- CVE-2020-9918
- CVE-2020-9923
- CVE-2020-9997
- CVE-2020-9920
- CVE-2020-9885
- CVE-2020-9881
- CVE-2020-9882
- CVE-2020-9985
- CVE-2020-9906
- CVE-2020-9942
- CVE-2020-9912
- CVE-2020-9903
- CVE-2020-9911
- CVE-2020-9931
- CVE-2020-9934
- CVE-2019-19906
- CVE-2020-9898
- CVE-2020-9917
Frequently Asked Questions
What is CVE-2020-9915?
CVE-2020-9915 is a vulnerability that existed in Content Security Policy in WebKit.
What software products are affected by CVE-2020-9915?
CVE-2020-9915 affects Apple Safari (up to version 13.1.2), Apple iOS (up to version 13.6), Apple iPadOS (up to version 13.6), Apple watchOS (up to version 6.2.8), Apple iCloud for Windows (up to version 7.20), Apple iTunes for Windows (up to version 12.10.8), and Apple tvOS (up to version 13.4.8).
How does CVE-2020-9915 impact users?
CVE-2020-9915 allows attackers to bypass Content Security Policy restrictions, potentially leading to unauthorized access to sensitive information.
What is the remedy for CVE-2020-9915?
To address CVE-2020-9915, users should update their affected Apple software products to the specified remediation versions.
Where can I find more information about CVE-2020-9915?
You can find more information about CVE-2020-9915 on Apple's support page: [link].