CVE-2020-20095 describes a URI spoofing vulnerability in Apple's iMessage (Messages app) on iOS 12.4 and earlier, where specially crafted messages can mislead users about the true destination of a link. This medium-severity vulnerability (CVSS 6.5) requires user interaction (UI:R) but can be exploited remotely (AV:N) with low attack complexity (AC:L), potentially leading to high integrity impacts (I:H) like phishing. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage, indicating awareness of its potential for phishing attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 12.4CPE matchmatch criteria | cpe:2.3:a:apple:imessage:*:*:*:*:*:iphone_os:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.