Junglewise Threat Intelligence

CVE-2020-3837: Apple Multiple Products Memory Corruption Vulnerability

CVE-2020-3837 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-06-27

Technologies: Apple watchOS, Apple iPadOS, Apple Tvos, Apple Multiple Products. Vendors: Apple.

Executive brief

A memory corruption vulnerability in Apple's operating systems (iOS, iPadOS, macOS, tvOS, and watchOS) allows an application to execute arbitrary code with kernel privileges. The issue was addressed through improved memory handling and is known to have been exploited in the wild.

Affected products

  • Apple iOS < 13.3.1
  • Apple iPadOS < 13.3.1
  • Apple macOS Catalina < 10.15.3
  • Apple tvOS < 13.3.1
  • Apple watchOS < 6.1.2

Timeline

  • 2020-02-27: disclosed: NVD Published Date
  • 2022-06-27: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2020-01-28: patched: Fixed in iOS 13.3.1, iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2

Related threats