Exploitation Summary
CVE-2020-3837 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 27, 2022. EIP tracks 1 public exploit from researchers including Google Security Research.
AI-analyzed exploit summary The writeup describes an out-of-bounds write vulnerability in IOAccelCommandQueue2::processSegmentKernelCommand() due to incorrect size checks, allowing overwrites of adjacent memory. The issue affects iOS 13 and potentially macOS, with a PoC available for iPod9,1 17B111.
Description
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.
Exploits (1)
The writeup describes an out-of-bounds write vulnerability in IOAccelCommandQueue2::processSegmentKernelCommand() due to incorrect size checks, allowing overwrites of adjacent memory. The issue affects iOS 13 and potentially macOS, with a PoC available for iPod9,1 17B111.
References (5)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H