CVE-2020-9907

HIGH KEV

iPadOS < 13.6 - Out-of-bounds Write

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-9907 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 27, 2022.

Description

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges.

References (3)

Core 3
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/HT211288
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/HT211290

Scores

CVSS v3 7.8
EPSS 0.0051
EPSS Percentile 67.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-06-27
VulnCheck KEV 2022-06-23
InTheWild.io 2022-06-27
ENISA EUVD EUVD-2020-30686
CWE
CWE-787
Status published
Products (3)
apple/ipados < 13.6
apple/iphone_os < 13.6
apple/tvos < 13.4.8
Published Oct 16, 2020
KEV Added Jun 27, 2022
Tracked Since Feb 18, 2026