Record summary

CVE-2020-9907 has a selected CVSS score of 7.8 (high). CISA lists CVE-2020-9907 in KEV.

Description

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Jun 27, 2022 · CISA
VulnCheck KEV
Listed · Jun 23, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE ListBefore iOS 13.6 and iPadOS 13.6affected
CVE ListBefore tvOS 13.4.8affected

References

4