CVE-2020-9945: Apple Mac OS X

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, Safari 14.0.1. Visiting a malicious website may lead to address bar spoofing.

Affected products

  • Apple Mac OS X: before 11.0.1 (fixed in 11.0.1)
  • Apple Safari: before 14.0.1 (fixed in 14.0.1)

Published 2020-12-08. Last modified 2026-06-17.