Vulnerabilities > CVE-2020-3852 - Incorrect Authorization vulnerability in Apple Safari

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
apple
CWE-863

Summary

A logic issue was addressed with improved validation. This issue is fixed in Safari 13.0.5. A URL scheme may be incorrectly ignored when determining multimedia permission for a website.

Vulnerable Configurations

Part Description Count
Application
Apple
173

Common Weakness Enumeration (CWE)

The Hacker News

idTHN:1D059A29F13AF81A28C2D2770E5CD2E6
last seen2020-04-03
modified2020-04-03
published2020-04-03
reporterThe Hacker News
sourcehttps://thehackernews.com/2020/04/hacking-iphone-macbook-camera.html
titleHow Just Visiting A Site Could Have Hacked Your iPhone or MacBook Camera