CVE-2020-9907

HIGH KEV

Apple Ipados < 13.6 - Out-of-Bounds Write

Title source: rule

Description

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges.

Scores

CVSS v3 7.8
EPSS 0.0051
EPSS Percentile 66.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-06-27
VulnCheck KEV 2022-06-23
InTheWild.io 2022-06-27
ENISA EUVD EUVD-2020-30686
CWE
CWE-787
Status published
Products (3)
apple/ipados < 13.6
apple/iphone_os < 13.6
apple/tvos < 13.4.8
Published Oct 16, 2020
KEV Added Jun 27, 2022
Tracked Since Feb 18, 2026