Apple iOS 13.5 and iPadOS 13.5-CVE-2020-9818
NAME
Apple – Multiple
- Platforms Affected:
Multiple - Risk Level:
medium - CVE Type:
Out-of-bounds write
DESCRIPTION
CVE-2020-9818 is an out-of-bounds write vulnerability impacting Apple iOS 13.4.1 and iPadOS 13.4.1 and earlier, Apple iOS versions 12.4.6 and earlier and Apple watchOS versions 6.2.1 and earlier. A proof of concept (PoC) was not observed publicly or in the underground. Security researchers at the Cybersecurity and Infrastructure Security Agency (CISA) claimed the vulnerability was actively exploited in the wild.
CVSS Information:
- CVSS 2.0 SCORE: 6.8
- CVSS 3.0 SCORE: 8.8
- Exploit Disclosed in the Public:
true - Exploit Weaponised:
true - PoC Link:
hXXps://www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog
MITIGATION
Apple addressed the vulnerability in multiple security advisories with updated versions.
- Reference Link:
https://support.apple.com/en-gb/HT211168 - Patch Available:
available
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.