An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.0.1. Processing a maliciously crafted document may lead to a cross site scripting attack.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT211931 | release notes vendor advisory |
https://support.apple.com/kb/HT212011 | vendor advisory |
http://seclists.org/fulldisclosure/2020/Dec/32 | third party advisory mailing list |
http://seclists.org/fulldisclosure/2020/Dec/26 | third party advisory mailing list |