CVE-2020-9951: Use After Free
A flaw was found in WebKitGTK. An use after free issue was addressed with improved memory management. Processing maliciously crafted web content may lead to arbitrary code execution.
Reference: https://webkitgtk.org/security/WSA-2020-0008.html
Other sources
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.
— Launchpad
Apple Safari could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in the WebKit component. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
WebKit. A use after free issue was addressed with improved memory management.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9979
- CVE-2020-9943
- CVE-2020-9944
- CVE-2020-9960
- CVE-2020-9954
- CVE-2020-9949
- CVE-2020-9999
- CVE-2020-9965
- CVE-2020-9966
- CVE-2020-29629
- CVE-2020-9956
- CVE-2020-9962
- CVE-2020-27931
- CVE-2020-29639
- CVE-2020-9978
- CVE-2020-36521
- CVE-2020-9961
- CVE-2020-9955
- CVE-2020-9876
- CVE-2020-9967
- CVE-2020-9975
- CVE-2020-9976
- CVE-2020-9981
- CVE-2020-9971
- CVE-2020-9969
- CVE-2020-9968
- CVE-2020-13434
- CVE-2020-13435
- CVE-2020-9991
- CVE-2020-15358
- CVE-2020-13631
- CVE-2020-9849
- CVE-2020-13630
- CVE-2020-9947
- CVE-2020-9950
- CVE-2020-9951
- CVE-2020-9983
- CVE-2020-9952
- CVE-2020-10013
- CVE-2020-9941
- CVE-2020-9989
- CVE-2020-9946
- CVE-2020-9993
- CVE-2020-10002
- CVE-2020-27912
- CVE-2020-27917
- CVE-2020-27911
- CVE-2020-27918
- CVE-2020-9987
- CVE-2020-9948
- CVE-2020-9958
- CVE-2020-9773
- CVE-2020-9992
- CVE-2020-9964
- CVE-2019-14899
- CVE-2020-9988
- CVE-2020-13520
- CVE-2020-6147
- CVE-2020-9972
- CVE-2020-9973
- CVE-2020-9996
- CVE-2020-9963
- CVE-2020-9977
- CVE-2020-9959
Frequently Asked Questions
What is CVE-2020-9951?
CVE-2020-9951 is a vulnerability in WebKit that allows for a use after free issue.
Which software is affected by CVE-2020-9951?
CVE-2020-9951 affects Apple iTunes for Windows (up to version 12.10.9), Apple iCloud for Windows (up to version 11.5), Apple watchOS (up to version 7.0), Apple iOS (up to version 14.0), Apple iPadOS (up to version 14.0), Apple Safari (up to version 14.0), and Apple tvOS (up to version 14.0).
How can I fix CVE-2020-9951?
To fix CVE-2020-9951, make sure to update your affected software to the recommended versions provided by Apple.
Where can I find more information about CVE-2020-9951?
You can find more information about CVE-2020-9951 on the official Apple support page.
What is the severity of CVE-2020-9951?
The severity of CVE-2020-9951 is not specified.