cbcvebase.
CVE-2020-3837
published 2020-02-27

CVE-2020-3837: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS…

PriorityP183high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-07-18
Exploited in the wild
EPSS
16.11%
96.6th percentile
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.

Affected

9 ranges
VendorProductVersion rangeFixed in
appleios>= unspecified < iOS 13.3.1 and iPadOS 13.3.1iOS 13.3.1 and iPadOS 13.3.1
appleipados< 13.3.113.3.1
appleiphone_os< 13.3.113.3.1
applemac_os_x< 10.15.310.15.3
applemacos>= unspecified < macOS Catalina 10.15.3macOS Catalina 10.15.3
appletvos< 13.3.113.3.1
appletvos>= unspecified < tvOS 13.3.1tvOS 13.3.1
applewatchos< 6.1.26.1.2
applewatchos>= unspecified < watchOS 6.1.2watchOS 6.1.2

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/48035.zip
  • Monitor for exploitation of IOAccelCommandQueue2::processSegmentKernelCommand() via command type 2 (kIOAccelKernelCommandCollectTimeStamp), which triggers an out-of-bounds write into the subsequent memory page via shared memory.
  • Look for userspace processes interacting with AGXCommandQueue shared memory in a way that triggers out-of-bounds timestamp writes — the OOB write is visible to userspace via shared memory, making it a detectable side-effect.
  • Flag applications attempting to execute arbitrary code with kernel privileges on unpatched Apple devices (iOS < 13.3.1, macOS < 10.15.3, tvOS < 13.3.1, watchOS < 6.1.2).
  • ·The PoC was confirmed on iOS 13 (iPod9,1 17B111) but the researcher notes macOS applicability was not directly tested.
  • ·The researcher suspects further shared memory volatility issues exist in AGXCommandQueue beyond the specific OOB timestamp write, meaning the attack surface may be broader than this single CVE.
  • ·Prior double-fetch vulnerabilities in AGXAllocationList2::initWithSharedResourceList() were fixed between firmware versions 16A5288q and 16G77; defenders should confirm patch levels carefully across all Apple product lines.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.