Junglewise Threat Intelligence

CVE-2020-9859: Apple Multiple Products Code Execution Vulnerability

CVE-2020-9859 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Apple Tvos, Apple iPadOS, Apple watchOS, Apple Multiple Products. Vendors: Apple.

Executive brief

A memory consumption issue (double free) in the Apple kernel allows a local application to execute arbitrary code with kernel privileges. The vulnerability was addressed through improved memory handling across multiple Apple operating systems.

Affected products

  • Apple iOS up to (excluding) 13.5.1
  • Apple iPadOS up to (excluding) 13.5.1
  • Apple macOS Catalina up to (excluding) 10.15.5 Supplemental Update
  • Apple tvOS up to (excluding) 13.4.6
  • Apple watchOS up to (excluding) 6.2.6

Timeline

  • 2020-06-05: disclosed: NVD Published Date
  • 2020-06-01: patched: Apple released updates for iOS, iPadOS, macOS, tvOS, and watchOS.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: exploited: Reported as exploited in the wild.

Related threats