Browser

Authentication & Access Bypass

Safari video permission spoof

Safari video permission spoof Using this vulnerability an attacker can trick the victim to grant website permissions to a website they didn’t intend to

5.3
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS32
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-9781
VENDORS
Apple
PUBLIC EXPLOIT
None indexed
CWE
CWE-281
PRODUCT
Safari (iOS)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Safari video permission spoof

Using this vulnerability an attacker can trick the victim to grant website permissions to a website they didn’t intend to

Vulnerability details

Vulnerability details

CVE-2020-9781
CWE-281
Medium | 5.3

Safari video permission spoof Using this vulnerability an attacker can trick the victim to grant website permissions to a website they didn’t intend to

Auth:
None (remote)
Impact:
Limited data tampering
DISCLOSURE

Disclosure timeline

2019-08-05 reported to the vendor

2020-03-25 coordinated public release of advisory

Credits

Nikhil Mittal