A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Copying a URL from Web Inspector may lead to command injection.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  Debian DSA | 
                DSA-4739-1 | webkit2gtk security update | 
  EUVD | 
                EUVD-2020-30641 | A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Copying a URL from Web Inspector may lead to command injection. | 
  Ubuntu USN | 
                USN-4444-1 | WebKitGTK vulnerabilities | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Mon, 07 Jul 2025 14:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Redhat rhel Els
         | 
|
| CPEs | cpe:/o:redhat:rhel_els:7 | |
| Vendors & Products | 
        
        Redhat rhel Els
         | 
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2024-08-04T10:43:05.449Z
Reserved: 2020-03-02T00:00:00
Link: CVE-2020-9862
No data.
Status : Modified
Published: 2020-10-16T17:15:15.433
Modified: 2024-11-21T05:41:25.710
Link: CVE-2020-9862
                        OpenCVE Enrichment
                    No data.
 Debian DSA
 EUVD
 Ubuntu USN