Executive brief
A memory corruption vulnerability in Apple iOS, iPadOS, and watchOS Mail allows for heap corruption when processing a maliciously crafted email message. The issue stems from improper memory handling and was addressed by improving memory consumption management.
Affected products
- Apple iOS < 12.4.7, 13.0 to < 13.5
- Apple iPadOS < 13.5
- Apple watchOS < 5.3.7, 6.0 to < 6.2.5
Timeline
- 2020-06-09: disclosed: NVD Published Date
- 2020-05-20: patched: Fixed in iOS 13.5, iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, and watchOS 5.3.7
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV catalog entry.