what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Apple Security Advisory 2020-09-16-4

Apple Security Advisory 2020-09-16-4
Posted Sep 18, 2020
Authored by Apple | Site apple.com

Apple Security Advisory 2020-09-16-4 - watchOS 7.0 is now available and addresses cross site scripting vulnerabilities.

tags | advisory, vulnerability, xss
systems | apple
advisories | CVE-2020-9946, CVE-2020-9952, CVE-2020-9968, CVE-2020-9976
SHA-256 | 7f2be0ff36ed50f74ec3888638f8ae775f5077dd53d9d1b8c3925c3c8b82ce89

Apple Security Advisory 2020-09-16-4

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-2020-09-16-4 watchOS 7.0

watchOS 7.0 is now available and addresses the following:

Keyboard
Available for: Apple Watch Series 3 and later
Impact: A malicious application may be able to leak sensitive user
information
Description: A logic issue was addressed with improved state
management.
CVE-2020-9976: Rias A. Sherzad of JAIDE GmbH in Hamburg, Germany

Phone
Available for: Apple Watch Series 3 and later
Impact: The screen lock may not engage after the specified time
period
Description: This issue was addressed with improved checks.
CVE-2020-9946: Daniel Larsson of iolight AB

Sandbox
Available for: Apple Watch Series 3 and later
Impact: A malicious application may be able to access restricted
files
Description: A logic issue was addressed with improved restrictions.
CVE-2020-9968: Adam Chester(@xpn) of TrustedSec

WebKit
Available for: Apple Watch Series 3 and later
Impact: Processing maliciously crafted web content may lead to a
cross site scripting attack
Description: An input validation issue was addressed with improved
input validation.
CVE-2020-9952: Ryan Pickren (ryanpickren.com)

Additional recognition

Bluetooth
We would like to acknowledge Andy Davis of NCC Group for their
assistance.

Core Location
We would like to acknowledge Yiğit Can YILMAZ (@yilmazcanyigit) for
their assistance.

iBoot
We would like to acknowledge Brandon Azad of Google Project Zero for
their assistance.

Kernel
We would like to acknowledge Brandon Azad of Google Project Zero for
their assistance.

Location Framework
We would like to acknowledge an anonymous researcher for their
assistance.

Safari
We would like to acknowledge Andreas Gutmann (@KryptoAndI) of
OneSpan's Innovation Centre (onespan.com) and University College
London, Steven J. Murdoch (@SJMurdoch) of OneSpan's Innovation Centre
(onespan.com) and University College London, Jack Cable of Lightning
Security, and an anonymous researcher for their assistance.

Installation note:

Instructions on how to update your Apple Watch software are
available at https://support.apple.com/kb/HT204641

To check the version on your Apple Watch, open the Apple Watch app
on your iPhone and select "My Watch > General > About".

Alternatively, on your watch, select "My Watch > General > About".
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEbURczHs1TP07VIfuZcsbuWJ6jjAFAl9igqcACgkQZcsbuWJ6
jjAWSw/8DKaYHQ01EPfcTwIcNJBQzwuzwsM6Veo5D9q7asIoxPBAvPa/aFEmypLC
+yMwvYY+/skjhLs7hx/fkxBelikQ8yPyIbqkfkoR4n3kpApDHhn0i1tRhhwNFeP1
Pd20DB1y2+enHIF3fQDWkywp72s1sjrBCtm47xVbZ9Z2mhHWaoOw3Cj8m/qr1ZfF
hA+CI9T1ubNEstDo596BqbiSnJfAYM3GlpEcGZr8UpXsP9LSlbgAUwum47LrZGCS
bAbgg1KiyQZ0ATbxwjbWG5UUo64SX/fkE/09xo6M3VKg3JqQ3kgzakCX+UX0lzVh
u5PFmg1IQ0fjMlP3Sy19Bf8gHfAvDbWwFs8IRSMH0RZLercL/ycpkHxPEMawydOt
UnMaqec4lKcWLZclv+/WbqLQ/206gQPXS7pFNQ6Mn/IIpMqCdJgA2LNsjXdyX9+8
vvsbvOen6X29yM6WonO6fj9438zX1hP2SgnPLx9jkvx911lD4qGGQ0pCfWFln8bR
Bgi8I9Ubv7NXoyT9y+vnaxb/z/mGc+aVKQaFrSQWJ+hD5gTrhMvSizE8Fsz2eZs8
UXU70WZ5REaFauGSVsrF56TPB1SAvxW21vP6ALKc1RP4kBIrSTdr822c/0jtM3VI
YZ/Zi4Bew4vSUOqIRGw8oUfyIiP5lt2FLOEHN8Mtpvin24KOVW4=
=5wu7
-----END PGP SIGNATURE-----


Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    17 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close