CVE-2020-9771
published 2020-10-22CVE-2020-9771: This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A user may gain access to protected parts of the file system.
PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.34%
26.9th percentile
This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A user may gain access to protected parts of the file system.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.15.4 | 10.15.4 |
| apple | macos | >= unspecified < macOS Catalina 10.15.4 | macOS Catalina 10.15.4 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
blogs_bleepingcomputer·2025-07-28·CVSS 7.1
CVE-2020-9771 [HIGH] Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
## Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
## Sergiu Gatlan
Since 2020, Apple has patched other TCC bypasses that exploit Time Machine mounts ( CVE-2020-9771 ), environment variable poisoning ( CVE-2020-9934 ), and a bundle conclusion issue ( CVE-2021-30713 ) . In the past, Microsoft security researchers have also discovered several other TCC bypasses, including powerdir ( CVE-2021-30970 ) and HM-Surf , that could also be abused to gain access to users' private data.
"While similar to prior TCC bypasses like HM-Surf and powerdir, the implications of this vulnerability, which we refer to as 'Sploitlight' for its use of Spotlight plugins, are more severe due to its ability to extract and leak sensitive information cached by Apple Intelligence, such as precise geol
Sentinelone
Bypassing macOS TCC User Privacy Protections By Accident and Design
blogs_sentinelone·2021-07-01
Bypassing macOS TCC User Privacy Protections By Accident and Design
## Bypassing macOS TCC User Privacy Protections By Accident and Design
## Executive Summary
TCC is meant to protect user data from unauthorized access, but weaknesses in its design mean that protections are easily overridden inadvertently.
Automation, by design, allows Full Disk Access to be ‘backdoored’ while also lowering the authorization barrier.
Multiple partial and full TCC bypasses are known, with several actively exploited in the wild.
TCC does not prevent processes reading and writing to ‘protected’ locations, a loophole that can be used to hide malware.
## Introduction
In recent years, protecting sensitive user data on-device has become of increasing importance, particularly now that our phones, tablets and computers are used for creating, storing and transmitting the most
Sentinelone
Bypassing macOS TCC User Privacy Protections By Accident and Design - SentinelLabs
blogs_sentinelone·2021-07-01
Bypassing macOS TCC User Privacy Protections By Accident and Design - SentinelLabs
## Executive Summary
- TCC is meant to protect user data from unauthorized access, but weaknesses in its design mean that protections are easily overridden inadvertently.
- Automation, by design, allows Full Disk Access to be ‘backdoored’ while also lowering the authorization barrier.
- Multiple partial and full TCC bypasses are known, with several actively exploited in the wild.
- TCC does not prevent processes reading and writing to ‘protected’ locations, a loophole that can be used to hide malware.
## Introduction
In recent years, protecting sensitive user data on-device has become of increasing importance, particularly now that our phones, tablets and computers are used for creating, storing and transmitting the most sensitive data about us: from selfies and family videos to passwor
2020-10-22
Published