cbcvebase.
CVE-2020-9818
published 2020-06-09

CVE-2020-9818: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5…

PriorityP180high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
2.29%
81.2th percentile
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5. Processing a maliciously crafted mail message may lead to unexpected memory modification or application termination.

Affected

7 ranges
VendorProductVersion rangeFixed in
appleios>= unspecified < iOS 13.5 and iPadOS 13.5iOS 13.5 and iPadOS 13.5
appleios-1>= unspecified < iOS 12.4.7iOS 12.4.7
appleipados< 13.513.5
appleiphone_os< 12.4.712.4.7
appleiphone_os>= 13.0 < 13.513.5
applewatchos< 6.2.56.2.5
applewatchos>= unspecified < watchOS 6.2.5watchOS 6.2.5

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2020-9818 is an out-of-bounds write flaw originating from the MFMutableData interface in the MIME framework in iOS; the flaw exists because MFMutableData does not handle errors from the ftruncate() system call
  • On iOS 13, the heap overflow (CVE-2020-9819) can be triggered zero-click via a specially crafted email; on iOS 12, user interaction (clicking the email) is required unless the attacker controls the mail server
  • CVE-2020-9818 (out-of-bounds write) requires an additional vulnerability allowing an arbitrary selector call to trigger remotely; monitor for chained exploit activity involving the iOS Mail app
  • Exploitation is delivered via a specially crafted email to the victim; detection should focus on anomalous or oversized email messages processed by the iOS Mail app
  • ZecOps (who named the exploit chain 'MailDemon') observed in-the-wild exploitation as early as January 2018 against iOS 11.2.2; threat hunting should consider historical mail logs from that period onward
  • Successful exploitation grants attacker capability to leak, modify, or delete emails within the Mail app context; monitor for unexpected Mail app data access or modification
  • Known targeted victims include Fortune 500 employees, carrier executives, managed security service providers, and journalists; prioritize investigation for these high-value target profiles

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.