CVE-2020-9805 is a universal cross-site scripting (UXSS) vulnerability affecting multiple Apple products, including iOS, iPadOS, tvOS, watchOS, Safari, iTunes for Windows, and iCloud for Windows. The vulnerability, rated High severity (CVSS 7.1), stems from a logic issue that, when processing maliciously crafted web content, could allow an attacker to execute arbitrary scripts in the context of the user's browser. While the vulnerability has a low EPSS score and no known public exploits or active exploitation, it poses a risk due to its potential for widespread impact across Apple's ecosystem. Apple addressed this issue with improved restrictions in various product updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.19CPE matchmatch criteria | cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:* | ||
>= 11.0, < 11.2CPE matchmatch criteria | cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:* | ||
< 12.10.7CPE matchmatch criteria | cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:* | ||
< 13.1.1CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 13.5CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.