Description
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iTunes 12.10.1 for Windows. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
References (8)
Core 8
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210634
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210722
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210604
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210606
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210607
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210635
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210636
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210637
Scores
CVSS v3
9.8
EPSS
0.0231
EPSS Percentile
84.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-125
Status
published
Products (6)
apple/icloud
< 7.14
apple/iphone_os
< 13.1
apple/itunes
< 12.10.1
apple/mac_os_x
< 10.15
apple/tvos
< 13
apple/watchos
< 6.0
Published
Oct 27, 2020
Tracked Since
Feb 18, 2026