Executive brief
An out-of-bounds write vulnerability in the Mail component of Apple iOS, iPadOS, and watchOS allows for memory modification or application termination. The flaw is triggered when the system processes a maliciously crafted email message and was addressed through improved bounds checking.
Affected products
- Apple iOS < 12.4.7, 13.0 to < 13.5
- Apple iPadOS < 13.5
- Apple watchOS < 6.2.5
Timeline
- 2020-06-09: disclosed: NVD Published Date
- 2020-05-20: patched: Fixed in iOS 13.5, iPadOS 13.5, iOS 12.4.7, and watchOS 6.2.5
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog