Junglewise Threat Intelligence

CVE-2020-9818: Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability

CVE-2020-9818 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Apple watchOS, Apple iPadOS. Vendors: Apple.

Executive brief

An out-of-bounds write vulnerability in the Mail component of Apple iOS, iPadOS, and watchOS allows for memory modification or application termination. The flaw is triggered when the system processes a maliciously crafted email message and was addressed through improved bounds checking.

Affected products

  • Apple iOS < 12.4.7, 13.0 to < 13.5
  • Apple iPadOS < 13.5
  • Apple watchOS < 6.2.5

Timeline

  • 2020-06-09: disclosed: NVD Published Date
  • 2020-05-20: patched: Fixed in iOS 13.5, iPadOS 13.5, iOS 12.4.7, and watchOS 6.2.5
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats