Files
CVEs-PoC/2020/CVE-2020-9979.md
T
2024-06-18 02:51:15 +02:00

20 lines
936 B
Markdown

### [CVE-2020-9979](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9979)
![](https://img.shields.io/static/v1?label=Product&message=iOS%20and%20iPadOS&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=tvOS&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%2014.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=An%20attacker%20may%20be%20able%20to%20misuse%20a%20trust%20relationship%20to%20download%20malicious%20content&color=brighgreen)
### Description
A trust issue was addressed by removing a legacy API. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0. An attacker may be able to misuse a trust relationship to download malicious content.
### POC
#### Reference
- http://seclists.org/fulldisclosure/2020/Nov/19
#### Github
- https://github.com/ChiChou/sploits
- https://github.com/houjingyi233/macOS-iOS-system-security