CVE-2020-9942: Apple Mac OS X

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, Safari 13.1.2. Visiting a malicious website may lead to address bar spoofing.

Affected products

  • Apple Mac OS X: before 11.0.1 (fixed in 11.0.1)
  • Apple Safari: before 13.1.2 (fixed in 13.1.2)

Published 2020-12-08. Last modified 2026-06-17.