exploit the possibilities

Apple Security Advisory 2020-09-16-4

Apple Security Advisory 2020-09-16-4
Posted Sep 18, 2020
Authored by Apple | Site apple.com

Apple Security Advisory 2020-09-16-4 - watchOS 7.0 is now available and addresses cross site scripting vulnerabilities.

tags | advisory, vulnerability, xss
systems | apple
advisories | CVE-2020-9946, CVE-2020-9952, CVE-2020-9968, CVE-2020-9976
MD5 | d0cb12546d5aebcf540ac9c015984183

Apple Security Advisory 2020-09-16-4

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-2020-09-16-4 watchOS 7.0

watchOS 7.0 is now available and addresses the following:

Keyboard
Available for: Apple Watch Series 3 and later
Impact: A malicious application may be able to leak sensitive user
information
Description: A logic issue was addressed with improved state
management.
CVE-2020-9976: Rias A. Sherzad of JAIDE GmbH in Hamburg, Germany

Phone
Available for: Apple Watch Series 3 and later
Impact: The screen lock may not engage after the specified time
period
Description: This issue was addressed with improved checks.
CVE-2020-9946: Daniel Larsson of iolight AB

Sandbox
Available for: Apple Watch Series 3 and later
Impact: A malicious application may be able to access restricted
files
Description: A logic issue was addressed with improved restrictions.
CVE-2020-9968: Adam Chester(@xpn) of TrustedSec

WebKit
Available for: Apple Watch Series 3 and later
Impact: Processing maliciously crafted web content may lead to a
cross site scripting attack
Description: An input validation issue was addressed with improved
input validation.
CVE-2020-9952: Ryan Pickren (ryanpickren.com)

Additional recognition

Bluetooth
We would like to acknowledge Andy Davis of NCC Group for their
assistance.

Core Location
We would like to acknowledge Yiğit Can YILMAZ (@yilmazcanyigit) for
their assistance.

iBoot
We would like to acknowledge Brandon Azad of Google Project Zero for
their assistance.

Kernel
We would like to acknowledge Brandon Azad of Google Project Zero for
their assistance.

Location Framework
We would like to acknowledge an anonymous researcher for their
assistance.

Safari
We would like to acknowledge Andreas Gutmann (@KryptoAndI) of
OneSpan's Innovation Centre (onespan.com) and University College
London, Steven J. Murdoch (@SJMurdoch) of OneSpan's Innovation Centre
(onespan.com) and University College London, Jack Cable of Lightning
Security, and an anonymous researcher for their assistance.

Installation note:

Instructions on how to update your Apple Watch software are
available at https://support.apple.com/kb/HT204641

To check the version on your Apple Watch, open the Apple Watch app
on your iPhone and select "My Watch > General > About".

Alternatively, on your watch, select "My Watch > General > About".
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEbURczHs1TP07VIfuZcsbuWJ6jjAFAl9igqcACgkQZcsbuWJ6
jjAWSw/8DKaYHQ01EPfcTwIcNJBQzwuzwsM6Veo5D9q7asIoxPBAvPa/aFEmypLC
+yMwvYY+/skjhLs7hx/fkxBelikQ8yPyIbqkfkoR4n3kpApDHhn0i1tRhhwNFeP1
Pd20DB1y2+enHIF3fQDWkywp72s1sjrBCtm47xVbZ9Z2mhHWaoOw3Cj8m/qr1ZfF
hA+CI9T1ubNEstDo596BqbiSnJfAYM3GlpEcGZr8UpXsP9LSlbgAUwum47LrZGCS
bAbgg1KiyQZ0ATbxwjbWG5UUo64SX/fkE/09xo6M3VKg3JqQ3kgzakCX+UX0lzVh
u5PFmg1IQ0fjMlP3Sy19Bf8gHfAvDbWwFs8IRSMH0RZLercL/ycpkHxPEMawydOt
UnMaqec4lKcWLZclv+/WbqLQ/206gQPXS7pFNQ6Mn/IIpMqCdJgA2LNsjXdyX9+8
vvsbvOen6X29yM6WonO6fj9438zX1hP2SgnPLx9jkvx911lD4qGGQ0pCfWFln8bR
Bgi8I9Ubv7NXoyT9y+vnaxb/z/mGc+aVKQaFrSQWJ+hD5gTrhMvSizE8Fsz2eZs8
UXU70WZ5REaFauGSVsrF56TPB1SAvxW21vP6ALKc1RP4kBIrSTdr822c/0jtM3VI
YZ/Zi4Bew4vSUOqIRGw8oUfyIiP5lt2FLOEHN8Mtpvin24KOVW4=
=5wu7
-----END PGP SIGNATURE-----


Login or Register to add favorites

File Archive:

October 2020

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    25 Files
  • 2
    Oct 2nd
    13 Files
  • 3
    Oct 3rd
    1 Files
  • 4
    Oct 4th
    1 Files
  • 5
    Oct 5th
    15 Files
  • 6
    Oct 6th
    15 Files
  • 7
    Oct 7th
    15 Files
  • 8
    Oct 8th
    11 Files
  • 9
    Oct 9th
    3 Files
  • 10
    Oct 10th
    1 Files
  • 11
    Oct 11th
    1 Files
  • 12
    Oct 12th
    8 Files
  • 13
    Oct 13th
    12 Files
  • 14
    Oct 14th
    23 Files
  • 15
    Oct 15th
    4 Files
  • 16
    Oct 16th
    13 Files
  • 17
    Oct 17th
    1 Files
  • 18
    Oct 18th
    1 Files
  • 19
    Oct 19th
    27 Files
  • 20
    Oct 20th
    41 Files
  • 21
    Oct 21st
    18 Files
  • 22
    Oct 22nd
    10 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close