CVE-2020-3852 is a logic issue in Apple Safari, fixed in version 13.0.5, where a URL scheme could be incorrectly ignored when determining multimedia permissions for a website. This medium-severity vulnerability (CVSS 5.3) allows for low-impact integrity compromise, potentially enabling unauthorized access to device multimedia. While not actively exploited in the wild and lacking public exploit code, it has garnered some community and media attention, including reports of Apple paying bounties for similar issues.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.0.5CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 13.0CPE match | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.