CVE-2020-3864 Information

Description

A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17 iTunes 12.10.4 for Windows iCloud for Windows 10.9.2 tvOS 13.3.1 Safari 13.0.5 iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://support.apple.com/en-us/HT210918 https://support.apple.com/en-us/HT210920 https://support.apple.com/en-us/HT210922 https://support.apple.com/en-us/HT210923 https://support.apple.com/en-us/HT210947 https://support.apple.com/en-us/HT210948

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.8

Share on: