Junglewise Threat Intelligence

CVE-2020-9934: Apple iOS, iPadOS, and macOS Input Validation Vulnerability

CVE-2020-9934 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2022-09-08

Technologies: Cisco IOS, Apple macOS, Apple watchOS, Apple iPadOS. Vendors: Cisco, Apple.

Executive brief

An input validation issue in the handling of environment variables in Apple iOS, iPadOS, and macOS allows a local attacker to view sensitive user information. The vulnerability was addressed by improving validation logic in system updates.

Affected products

  • Apple iOS < 13.6
  • Apple iPadOS < 13.6
  • Apple macOS Catalina < 10.15.6

Timeline

  • 2020-10-16: disclosed: NVD Published Date
  • 2022-09-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2020-07-15: patched: Fixed in iOS 13.6, iPadOS 13.6, and macOS Catalina 10.15.6

Related threats