{"product_id":11060,"v_id":11060,"product_name":"Apple iOS 13 and iPadOS 13: Safari","certification_status":"Certified","certification_date":"2020-06-05T00:00:00Z","tech_type":"Application Software","vendor_id":{"name":"Apple Inc.","website":"https://support.apple.com/guide/certifications/welcome/web"},"vendor_poc":"Fiona Pattinson","vendor_phone":"16692273579","vendor_email":"Security-certifications@Apple.com","assigned_lab":{"cctl_name":"Acumen Security"},"product_description":"<p style=\"margin-bottom: .0001pt;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The TOE is the Apple iOS and iPadOS Safari application which runs on iPad and iPhone devices. The product provides access to HTTPS/TLS connections via a browser for user connectivity.</span></p>\r\n<p style=\"margin-bottom: .0001pt;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">Note: The TOE is the Safari software only. The Apple iOS and iPadOS operating systems are undergoing evaluation separately.</span></p>","evaluation_configuration":"<p style=\"margin-bottom: .0001pt;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\"><span style=\"mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;\">The TOE is an application on a mobile operating system. The Apple iOS and iPadOS operating systems are being separately validated</span> against the Protection Profile for Mobile Device Fundamentals Version 3.1<span style=\"mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;\">. The mobile operating system and hardware platforms are part of the TOE environment. The evaluated version of the TOE is version 13.4.1.&nbsp;</span></span></p>","security_evaluation_summary":"<p style=\"margin-bottom: .0001pt; line-height: normal;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The evaluation was carried out in accordance with the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The criteria against which the Apple iOS and iPadOS 13 Safari was evaluated are described in the Common Criteria for Information Technology Security Evaluation, Version 3.1 rev 5.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation, Version 3.1 rev 5.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The product, when delivered configured as identified in the Apple iOS and iPadOS 13 Safari Common Criteria Guide, satisfies all of the security functional requirements stated in the Apple iOS and iPadOS 13 Safari Security Target. The project underwent CCEVS Validator review.<span style=\"mso-spacerun: yes;\">&nbsp; </span>The evaluation was completed in <span style=\"mso-bidi-font-weight: bold;\">June 2020</span>.<span style=\"mso-spacerun: yes;\">&nbsp; </span>Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report prepared by CCEVS.&nbsp;</span></p>","environmental_strengths":"<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\"><span style=\"mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;\">The TOE provides the security functionality required by [SWAPP]</span> <span style=\"mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;\">and [WEBBROWSEREP].</span></span></p>\r\n<p style=\"text-indent: -.6in; line-height: normal; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 4; tab-stops: list 70.2pt; margin: 2.0pt 0in .0001pt .6in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-style: italic;\">Cryptographic Support</span></strong></span></p>\r\n<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The platform provides TLS/HTTPS connectivity for users attempting to communicate with secure URLs. The TOE does not directly perform any cryptographic functions. The TOE invokes the platform cryptography for secure credential storage.</span></p>\r\n<p style=\"text-indent: -.6in; line-height: normal; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 4; tab-stops: list 70.2pt; margin: 2.0pt 0in .0001pt .6in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-style: italic;\">User Data Protection</span></strong></span></p>\r\n<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The TOE requests access to network connectivity, camera, microphone, location services, and address book, and communicates with the wireless network when invoked by the user. The TOE runs inside of a sandbox where each browser tab is isolated. In addition, the TOE supports blocking of third-party cookies. When a cookie has been set with the &lsquo;secure&rsquo; attribute, the TOE will only send the cookie over HTTPS.</span></p>\r\n<p style=\"text-indent: -.6in; line-height: normal; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 4; tab-stops: list 70.2pt; margin: 2.0pt 0in .0001pt .6in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-style: italic;\">Security Management</span></strong></span></p>\r\n<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The platform provides the ability to configure the TOE. No credentials are installed by default.</span></p>\r\n<p style=\"text-indent: -.6in; line-height: normal; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 4; tab-stops: list 70.2pt; margin: 2.0pt 0in .0001pt .6in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-style: italic;\">Privacy</span></strong></span></p>\r\n<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">If the user logs into iCloud Account on two or more devices, two devices within Bluetooth range of each other have the ability to automatically &ldquo;continue&rdquo; browsing with the same URL provided via iCloud.</span></p>\r\n<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The TOE does not specifically request PII from the user. Any information provided by the user is entered without prompting from the TOE.</span></p>\r\n<p style=\"text-indent: -.6in; line-height: normal; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 4; tab-stops: list 70.2pt; margin: 2.0pt 0in .0001pt .6in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-style: italic;\">Protection of the TSF</span></strong></span></p>\r\n<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The TOE does not permit automatic downloads. All downloads are at the request of a user and require approval. The TOE does not support add-ons. The only supported mobile code is signed JavaScript. No third-party libraries are leveraged by the TOE. The TOE platform verifies all software updates via digital signature.</span></p>\r\n<p style=\"text-indent: -.6in; line-height: normal; mso-pagination: widow-orphan lines-together; page-break-after: avoid; mso-outline-level: 4; tab-stops: list 70.2pt; margin: 2.0pt 0in .0001pt .6in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\"><strong style=\"mso-bidi-font-weight: normal;\"><span style=\"mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-style: italic;\">Trusted Path/Channels</span></strong></span></p>\r\n<p style=\"line-height: normal; margin: 6.0pt 0in 6.0pt 0in;\"><span style=\"font-family: 'times new roman',times,serif; font-size: 12pt;\">The TOE is a software application. The TOE leverages the platform to establish HTTPS/TLS protected communications.</span></p>","features":[]}