Junglewise Threat Intelligence

CVE-2020-9819: Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability

CVE-2020-9819 · Severity: critical · CVSS 4.3 · Exploited in the wild · Published 2021-11-03

Technologies: Apple watchOS, Apple iPadOS. Vendors: Apple.

Executive brief

A memory corruption vulnerability in Apple iOS, iPadOS, and watchOS Mail allows for heap corruption when processing a maliciously crafted email message. The issue stems from improper memory handling and was addressed by improving memory consumption management.

Affected products

  • Apple iOS < 12.4.7, 13.0 to < 13.5
  • Apple iPadOS < 13.5
  • Apple watchOS < 5.3.7, 6.0 to < 6.2.5

Timeline

  • 2020-06-09: disclosed: NVD Published Date
  • 2020-05-20: patched: Fixed in iOS 13.5, iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, and watchOS 5.3.7
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV catalog entry.

Related threats