Junglewise Threat Intelligence

CVE-2020-9907: Apple Multiple Products Memory Corruption Vulnerability

CVE-2020-9907 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-06-27

Technologies: Apple Tvos, Apple iPadOS, Apple Multiple Products. Vendors: Apple.

Executive brief

A memory corruption vulnerability (specifically an out-of-bounds write) in Apple iOS, iPadOS, and tvOS allows an application to execute arbitrary code with kernel privileges. The issue was addressed by removing the vulnerable code in updates.

Affected products

  • Apple iOS < 13.6
  • Apple iPadOS < 13.6
  • Apple tvOS < 13.4.8

Timeline

  • 2020-10-16: disclosed: NVD Published Date
  • 2022-06-27: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-27: exploited: Reported as exploited in the wild
  • 2020-07-15: patched: Fixed in iOS 13.6, iPadOS 13.6, and tvOS 13.4.8

Related threats