CVE-2020-3837

HIGH KEV

iPadOS < 13.3.1 - Out-of-bounds Write

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-3837 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 27, 2022. EIP tracks 1 public exploit from researchers including Google Security Research.

AI-analyzed exploit summary The writeup describes an out-of-bounds write vulnerability in IOAccelCommandQueue2::processSegmentKernelCommand() due to incorrect size checks, allowing overwrites of adjacent memory. The issue affects iOS 13 and potentially macOS, with a PoC available for iPod9,1 17B111.

Description

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/48035

The writeup describes an out-of-bounds write vulnerability in IOAccelCommandQueue2::processSegmentKernelCommand() due to incorrect size checks, allowing overwrites of adjacent memory. The issue affects iOS 13 and potentially macOS, with a PoC available for iPod9,1 17B111.

Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Apple IOAccelCommandQueue2 (iOS 13, potentially macOS)
No auth needed
Prerequisites: Access to shared memory in the target system · Ability to craft malicious IOAccelKernelCommand structures
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/HT210919
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/HT210918
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/HT210921
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/HT210920

Scores

CVSS v3 7.8
EPSS 0.1611
EPSS Percentile 96.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-06-27
VulnCheck KEV 2022-06-23
InTheWild.io 2022-06-27
ENISA EUVD EUVD-2020-25102
CWE
CWE-787
Status published
Products (5)
apple/ipados < 13.3.1
apple/iphone_os < 13.3.1
apple/mac_os_x < 10.15.3
apple/tvos < 13.3.1
apple/watchos < 6.1.2
Published Feb 27, 2020
KEV Added Jun 27, 2022
Tracked Since Feb 18, 2026